Product Affected

All releases of the JUNOS Internet software
None

Problem

The CERT Coordination Center (CERT/CC) has recently issued an advisory describing two possible areas of vulnerability in implementations of the RADIUS protocol. These are identified by CERT/CC as:

  • VU#589523 - Multiple implementations of the RADIUS protocol contain a Digest Calculation buffer overflow
  • VU#936683 - Multiple implementations of the RADIUS protocol do not adequately validate the Vendor-Specific attribute Vendor-Length


Juniper Networks has examined its implementation of RADIUS and has determined that it is not susceptible to either of these potential vulnerabilities.

Solution

No action is required.

No action is required.

Severity Assessment

All releases of the JUNOS software are free of risk from these vulnerabilities.

Related Information