This Security Advisory updates PSN-2009-01-200. Several issues with JUNOS sending & receiving malformed BGP 4-Byte transitive attributes have been seen operationally on the Internet. JUNOS routers which receive these malformed attributes will strictly comply with the BGP specs and drop the BGP session. This issue has been previously addressed a prior Security Advisory - PSN-2009-01-200 (BGP Session Teardown due to AS_CONFED_SEQUENCE in AS4_PATH). This Security Advisory provides an update and further details from an extensive audit to remediate this issue. As previously mentioned, when sending a BGP UPDATE message, JUNOS may include the following segment types in the AS4_path attribute:
* AS_CONFED_SEQUENCE{*} * AS_CONFED_SET{*}
Customers are recommended to upgrade JUNOS through planned and methodical upgrade processes. All JUNOS software releases built on or after January 21, 2009 has fixed malformed BGP transitive attribute issues. This specifically includes 9.1R4, 9.2-20090130-SR, 9.2R4, 9.3-20090227-SR, 9.3R3, 9.4R1, and all subsequent releases. The PRs for this issue are 417046. This only impact JUNOS from 9.1R1 forward. 4-byte ASNs were introduced in JUNOS in 9.1R1 (released before 20090126).
How to obtain Service Releases: Security vulnerabilities are fixed in the next available Maintenance Release of each supported JUNOS version. In some cases, a Maintenance Release is not planned to be available in an appropriate time-frame. For these cases, Service Releases are made available in order to be more timely. Security Advisory notices will indicate which Maintenance and/or Service Releases contain fixes for the issues described. Upon request to JTAC, customers will be provided download instructions for a Service Release. Although Juniper does not provide formal Release Note documentation for a Service Release, a list of "PRs fixed" can be provided on request.