The OpenSSL project released a security advisory on 2014-08-06 that contained nine security issues. The following four issues affect Junos: CVE-2014-5139 : Crash with SRP ciphersuite in Server Hello message CVE-2014-3509 : Race condition in ssl_parse_serverhello_tlsext CVE-2014-3511 : OpenSSL TLS protocol downgrade attack CVE-2014-3512 : SRP buffer overrun More information about each of these vulnerabilities may be found in the OpenSSL Security Advisory 20140806 under Related Links below.
Since SSL is used for remote network configuration and management applications such as J-Web and SSL Service for JUNOScript (XNM-SSL), viable workarounds for this issue in Junos may include: