Product Affected

All releases of JUNOS software built prior to March 13, 2003
Low

Problem

Versions of OpenSSL software shipped with JUNOS releases built prior to March 13, 2003 do not perform a MAC checksum calculation on packets that contain incorrect block cipher padding. An attacker can detect the difference in the amount of time required for reporting incorrect padding errors and reporting MAC checksum verification errors. Being able to distinguish between the two types of errors can aid an attacker in devising more effective attacks against certain encryption algorithms.

More details can be found at http://www.openssl.org/news/secadv_20030219.txt. This problem is documented as PR/32421.

Solution

All JUNOS software built on or after March 13, 2003 performs the MAC checksum calculation on all packets, including packets with incorrect block cipher padding. The code now takes nearly the same amount of time to report both types of errors. This effectively prevents an attacker from distinguishing between the two types of errors based on response time, and from using that information to improve the attack.

Customers should install a release of JUNOS built on or after March 13, 2003.

Severity Assessment

No known exploit of this vulnerability exists.