CTPView release 7.0R1 addresses multiple vulnerabilities in prior releases with updated third party software components. Following is a list of software upgraded and vulnerabilities resolved:
Linux Kernel was upgraded to version 2.6.18-371.1.2.el5 which resolved:
Oracle MySQL package was upgraded to 5.1.66 which resolved:
Vulnerabilities addressed in Apache Reverse Proxy:
Sudo package was upgraded to 1.7.10p7 which resolved:
PHP package was upgraded to 5.2.17-2 which resolved:
Libxml2 library was upgraded to resolve:
Mozilla NSS and NSPR packages were upgraded to resolve:
Vulnerabilities addressed in GNU C Library (glibc or libc6):
Vulnerabilities addressed in Linux PAM:
In addition to the above, third party software upgrades in CTPView contain fixes to a number other CVEs which are not exploitable on CTPView or not applicable in the context of CTPView or their impact to CTPView has not been evaluated. Hence those are not listed here.
Bash package was upgraded to version 3.2.33 to resolve "ShellShock" vulnerabilities (CVE-2014-6271 CVE-2014-7169). Hower CTPView was evaluated to be not vulnerable to any remote exploitation risks due to these issues.
These vulnerabilities are fixed in CTPView 7.0R1 and later releases.
CTPView release 7.0R1 is available for download from http://www.juniper.net/support/downloads/?p=ctpview#sw .
There are no known workarounds that can be used to mitigate all the above vulnerabilities. Limiting access to CTPView from only trusted hosts would help mitigate Apache, MySQL, sudo and PHP vulnerabilities.
2014-11-12: Initial publication. 2017-03-05: Category restructure.