Bash or the Bourne again shell has vulnerabilities in the way it handles environment variables when it is invoked. Under some scenarios, network based remote attackers can inject shell script that can be executed on a system. This is also known as "ShellShock". These issues have been assigned CVE-2014-6271 , CVE-2014-7169 , CVE-2014-7186 , CVE-2014-7187 , CVE-2014-6277 and CVE-2014-6278 .
Juniper is investigating our product portfolio for affected software that is not mentioned above. As new information becomes available this document will be updated.
Connect Secure (SA / SSL VPN) / MAG Series:
Fixes have been added to the following releases: 7.1r20.1,7.4r13.1 and 8.0r7 which are available for download from www.juniper.net/support/downloads/ .
JSA, STRM Series devices:
Patch for CVE-2014-7169 and rest of the CVEs is available for download from www.juniper.net/support/downloads/ . This patch resolve all the issues related to shellshock for all supported versions of JSA and STRM software releases.
NSM Appliances:
All the six CVEs are now fixed by " NSM Appliance Generic Offline Upgrade Package_v3 - CentOS 5.x " or " NSM Appliance Generic Online Upgrade Script_v3_CentOS5.x " (released Sep 30, 2014) or later. These are available for download from https://www.juniper.net/support/downloads/?p=nsm#sw . These issues are fixed in NSM 2012.2R9 and subsequent releases. For NSM Appliances with CentOS 4 based installations NSM Bash RPM update for CentOS 4 is available for download as an interim fix. Please see Implementation section for instructions.
Junos Space:
These issues are resolved in Junos Space 14.1R2 and all subsequent releases. For older releases Junos Space Bash Security Update v2 is available as an interim fix. This can be downloaded from Junos Space software download page .
IDP Series:
These issues are resolved in IDP OS 5.1r4 and all subsequent releases. Bash RPM update to resolve all these issues is available for download at the bottom of this page as an interim fix. Please see Implementation section for instructions.
Junos Content Encode (MFC):
All these issues are resolved in Junos Content Encore 12.3.8 or later versions, available for download from www.juniper.net/support/downloads/ .
SRC Series:
All these issues are resolved in SRC 4.4.0-R14, 4.5.0-R5, 4.6.0-R5, 4.7.0-R2, 4.8.0-R1 and subsequent releases.
Juniper has released signatures to detect this issue. Sigpack 2424 contains IDP signatures designed to detect CVE-2014-6271 and other CVEs associated with Shell Shock: HTTP:CGI:BASH-CODE-INJECTION HTTP:CGI:SHELLSHOCK DHCP:SERVER:GNU-BASH-CMD-EXE HTTP:CGI:BASH-INJECTION-HEADER HTTP:CGI:BASH-INJECTION-URL
We are currently investigating our product portfolio for affected software and will work to provide fixes for any software that is found to be vulnerable. This document will be updated with version information as product updates become available.
Updated software is available for download from www.juniper.net/support/downloads/ under Content & Media Delivery.
Workarounds for these issues include:
It is good security practice to limit the exploitable attack surface of critical infrastructure networking equipment irrespective of a product's exposure to this issue. Always Use access lists or firewall filters to limit access to the devices only from trusted, administrative networks or hosts.
Until NSM Appliance fixes are available, updated bash RPM bash-3.2-33.el5.1.i386.rpm or later version can be downloaded from http://mirror.centos.org/centos-5/5/updates/i386/RPMS/ and applied on the NSM Appliance. Updated bash RPM bash-3.0-22nsmShellShockFix.i386.rpm is available for Centos 4 based NSM installations.
Disabling the DMI agent (both inbound and outbound) should completely mitigate associated security risks.
2017-03-05: Category restructure.
Juniper SIRT would like to acknowledge and thank Stephane Chazelas for discovering CVE-2014-6271, Michal Zalewski for discovering CVE-2014-6277 and CVE-2014-6278, and Florian Weimer for responsibly coordinating disclosure of vulnerabilities.