Input from the "User:" prompt is not sanitized correctly when it is logged to the internal audit trail. If the input contains correctly composed, executable content, then it will be executed in the context of another user when that other user views the associated log entry (for example, when reviewing the audit trail on the device). If that other user is the administrator, then the executable content may be executed with root privileges. An attacker could exploit this vulnerability to supply a specially crafted script to the "User:" prompt on the login page which will be executed by a privileged user at some indeterminate future time when that privileged user views the resulting log entry. All STRM platforms running any 2008.* software version earlier than 2008.3 patch 530 are affected. All 2009.* series releases and later versions are NOT affected.
All software releases in the 2008.* series built on or after 2009-08-18 have been fixed for this issue. Releases containing the fix specifically include 2008.3 patch 530, 2009.1, and all subsequent releases. This issue is being tracked as "STRM PR 6692". The PR is not viewable by customers but the label can be used for reference when discussing the issue with JTAC. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our "End of Engineering" and "End of Life" support policies.
No known workaround exists for this issue. Care should be taken when reviewing logs and audit trails, especially if logged into an account with administrative privileges. Customers are urged to upgrade to fixed releases of software.