JUNOS software release 7.3R1.5 has been found to be vulnerable to attacks using TCP-based protocol packets. Any mismatch in MD5 authentication for packets sent to either configured or unconfigured TCP-based protocol peers on a Juniper Networks router running JUNOS Release 7.3R1.5 can result in a memory leak, which over time can cause a router restart.
This issue is tracked internally as PR/61535 for JUNOS software.
Changes have been made in JUNOS 7.3R1.6 software to mitigate the potential vulnerability of receiving packets with mismatched MD5 authentication to either configured or unconfigured TCP-based protocol peers.
JUNOS Release 7.3R1.6 contains modified code that provides expanded TCP and MD5 authentication checks.