Junos Space release 14.1R1 addresses multiple vulnerabilities in prior releases with updated third party software components. The following is a list of software upgraded and vulnerabilities resolved:
OpenJDK runtime 1.7.0 update_45 was upgraded to 1.7.0 update_65 which resolves:
OpenSSL CentOS package was upgraded from 0.9.8e-20 to 0.9.8e-27.el5 which resolves:
Oracle MySQL was upgraded from 5.5.34 to 5.5.36 which resolves:
These issues are fixed in Junos Space 14.1R1 and all subsequent releases.
Junos Space Releases are available at http://www.juniper.net/support/downloads/?p=space#sw .
Note: If you are upgrading to 14.1 from previous releases please download and install the bash security update v2 patch (even if Bash Security Update was previously installed). Please see http://kb.juniper.net/JSA10648 [juniper.net]
Use access lists or firewall filters to limit access to the Junos Space device only from trusted hosts.
2014-11-12: Initial publication. 2014-11-17: Corrected the Java and OpenSSL versions in 14.1R1, included additional CVEs that are resolved. 2016-09-07: Corrected the name of Java Runtime Environment used by Junos Space.