Product Affected
Various
Severity
None
Severity Assessment (CVSS) Score
N/A
Problem
A new Junos product security advisory bundle has been released. This message contains the link(s) to the new PSN advisories that have been released. In the interest of speeding the delivery process for SIRT Security Announcements, the Juniper SIRT has implemented a small process change. When the Juniper SIRT publishes Security Advisories and/or Security Notices, a single primary PSN (this PSN) will be pushed to subscribed customers which briefly lists the IDs, descriptions, and links for all of the individual Security Announcements being released together on that day.
Solution
Please see the following links for more information about the new security advisories:
PSN-2013-04-911: Junos: Specially crafted SIP packet can cause the flowd process to crash
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-04-911&viewMode=view
PSN-2013-04-912: Junos: SIP ALG on SRX Series may allow sessions not permitted by policy which can lead to a DoS
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-04-912&viewMode=view
PSN-2013-04-913: Junos: Kernel crash while processing certain types of ARP packets
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-04-913&viewMode=view
PSN-2013-04-914: Junos: J-Web Sajax remote code execution
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-04-914&viewMode=view
PSN-2013-04-915: Junos: MBUF exhaustion with IPv6 egress filter on the loopback interface
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-04-915&viewMode=view
PSN-2013-04-916: Junos: Ethernet traffic with invalid Ether-Type can trigger protocol packet drops on Ichip-based FPCs/DPCs
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-04-916&viewMode=view
PSN-2013-04-917: Junos: Kernel crash when receiving crafted GRE packet on multicast tunnel interface
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-04-917&viewMode=view
PSN-2013-04-918: Junos: DNSSEC validation Denial of Service (CVE-2012-3817)
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2013-04-918&viewMode=view
Workaround
N/A
Modification History
2013-04-10: Initial publication 2020-11-20: Updated terminology
Related Information
KB16613: Overview of the Juniper Networks SIRT Monthly Security Bulletin Publication Process
[juniper.net]
KB16765: In which releases are vulnerabilities fixed?
[juniper.net]
KB16446: Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories
[juniper.net]
Report a Vulnerability - How to Contact the Juniper Networks Security Incident Response Team
2013-04: Junos Routing, Switching, and Security: Security Advisories Released