NSM products incorporate a variant of the Apache web server, and some older versions of NSM software are affected by the vulnerability described in this document. Releases of the Apache web server prior to version 2.0.59 contain an off-by-one buffer overflow vulnerability which is encountered when escaping an absolute URI scheme. The vulnerability might be exploited to gain complete control of the affected NSM product. NSM Server does not include the Apache web server in its software distribution. NSM Server installations may or may not be vulnerable depending on what version of the Apache web server is running on the underlying platform as provided by the customer. This issue is being tracked as PR 308831. While this PR is not viewable by customers, it can be used as a reference when discussing the issue with JTAC.
The vulnerability was repaired by upgrading the version of software recommended below. The issue is fixed for NSMXpress, NSM Appliance, and NSM3000 in versions 4.116699, 2008.2r1, 2009.1r1, and all subsequent releases. As mentioned above, the web server is not included in NSM Server software, and the vulnerability, if present, will not be removed by upgrading to an unaffected version of NSM Server software. The issue can be addressed by upgrading the Apache web server on the underlying server or, if an upgrade is not possible, workarounds should be considered and applied.
Customers are strongly encouraged to upgrade to a current, unaffected version of software. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which releases are selected to receive fixes for vulnerabilities as per Juniper Networks' "End of Engineering" and "End of Life" support policies. If upgrading software is not possible, not feasible, or not likely to occur for some time, then a workaround should be employed. In all cases, customers should evaluate the risks and benefits of any given workaround to ensure that it is appropriate and practical in the customer's own production environment. How to obtain fixed software: NSM Maintenance Releases are available at http://support.juniper.net from the "Download Software" links. If a Maintenance Release is not adequate and access to NSM patches is needed, open a customer support case. A JTAC engineer will review your request and respond, ensuring that you will be provided with the most appropriate Patch Release for your specific situation.
LoadModule rewrite_module modules/mod_rewrite.so
LoadModule alias_module modules/mod_alias.so #LoadModule rewrite_module modules/mod_rewrite.so #LoadModule proxy_module modules/mod_proxy.so