Product Affected
Various
Severity
None
Severity Assessment (CVSS) Score
N/A
Problem
A new Routing and Switching product security advisory bundle has been released. This message contains the link(s) to the new PSN advisories that have been released.
In the interest of speeding the delivery process for SIRT Security Announcements, the Juniper SIRT has implemented a small process change. When the Juniper SIRT publishes Security Advisories and/or Security Notices, a single primary PSN (this PSN) will be pushed to subscribed customers which briefly lists the IDs, descriptions, and links for all of the individual Security Announcements being released together on that day.
Solution
Please see the following links for more information about the new security advisories:
PSN-2012-07-643: Incorrect behavior of SYN Cookie protection
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-643&viewMode=view
PSN-2012-07-644: Kernel crash due to ICMPv6 packet with corrupted payload
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-644&viewMode=view
PSN-2012-07-645: Incorrect integer conversions in OpenSSL can result in memory corruption (CVE-2012-2110)
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-645&viewMode=view
PSN-2012-07-646: Loading factory-default from exclusive edit causes escalation of privileges
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-646&viewMode=view
PSN-2012-07-647: rpd crash when receiving malformed IS-IS hello packets
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-647&viewMode=view
PSN-2012-07-648: rpd process can hang following a specific PIM broadcast storm
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-648&viewMode=view
PSN-2012-07-649: J-Web vulnerable to Cross Site Scripting
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-649&viewMode=view
PSN-2012-07-650: J-Web vulnerable to hash table collision attacks (CVE-2011-3414)
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-650&viewMode=view
PSN-2012-07-651: When 'log' action is enabled, a firewall filter deployed on lo0 cannot filter high rate of packets sent to the RE
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-651&viewMode=view
PSN-2012-07-652: flowd core when processing non-first IP fragmented packets
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-652&viewMode=view
PSN-2012-07-653: Inbound SSH traffic is allowed even though 'host-inbound-traffic' is not configured to allow it
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-07-653&viewMode=view
Workaround
N/A
Modification History
2012-11-07: Initial publication 2020-11-20: Updated terminology
2012-07: Routing and Switching: Security Advisories Released