Product Affected

Various
None
Various

Problem

A new Junos product security advisory bundle has been released. This message contains the link to the new Juniper Security Advisories (JSAs) that have been released.

In the interest of speeding the delivery process for SIRT Security Announcements, the Juniper SIRT has implemented a small process change. When the Juniper SIRT publishes Security Advisories and/or Security Notices, a single primary PSN (this PSN) will be pushed to subscribed customers which briefly lists the IDs, descriptions, and links for all of the individual Security Announcements being released together on that day.

Solution

Please see the following links for more information about the new security advisories: 

  1. JSA10573 [juniper.net] - SRX flowd core while processing PIM packets (CVE-2013-4684)
    http://kb.juniper.net/JSA10573 [juniper.net]
     
  2. JSA10574 [juniper.net] - SRX buffer overflow vulnerability in flowd while processing HTTP protocol messages in a UAC environment (CVE-2013-4685)
    http://kb.juniper.net/JSA10574 [juniper.net]
     
  3. JSA10575 [juniper.net] - Multiple security vulnerabilities in OpenSSL
    http://kb.juniper.net/JSA10575 [juniper.net]
     
  4. JSA10576 [juniper.net] - Kernel crash during processing of certain ARP requests when proxy-arp and arp-resp options enabled (CVE-2013-4686)
    http://kb.juniper.net/JSA10576 [juniper.net]
     
  5. JSA10577 [juniper.net] - Multiple SRX flowd crashes while processing certain TCP packets when TCP-based ALGs configured (CVE-2013-4687)
    http://kb.juniper.net/JSA10577 [juniper.net]
     
  6. JSA10578 [juniper.net] - SRX flowd core while processing MSRPC messages (CVE-2013-4688)
    http://kb.juniper.net/JSA10578 [juniper.net]
     
  7. JSA10579 [juniper.net] - SRX1400/3400/3600 vulnerable to 'Etherleak' packet fragment disclosure in Ethernet padding data (CVE-2013-4690)
    http://kb.juniper.net/JSA10579 [juniper.net]
     
  8. JSA10580 [juniper.net] - SSL/TLS Renegotiation DoS vulnerability detected in Junos (CVE-2011-1473)
    http://kb.juniper.net/JSA10580 [juniper.net]

Workaround

Not applicable.

Modification History

2013-07-09: Initial publication
2020-11-20: Updated terminology

Related Information