On January 27, 2015, Qualys announced the GHOST vulnerability: https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability The GHOST vulnerability is a serious weakness in the Linux glibc library. It allows attackers to remotely take complete control of the victim system without having any prior knowledge of system credentials. While there is no indication that Juniper products and services are vulnerable to remote exploitation, the following products do include the affected glibc library: Affected Products
Note: The PRs listed below are for tracking purposes and may not be visible on the external website.
tar -zxf glibc-ntp-hotpatch-vz.tgz
cd glibc-ntp-hotpatch-v1
sh patchme.sh
IMPORTANT
sh fixupgrade.sh 14.1R1.9 CLUSTER
unzip glibc-common-2.5-123.el5_11.1.i386.rpm.zip
rpm -Uvh unzip glibc-common-2.5-123.el5_11.1.i386.rpm.zip --nodeps
rpm -Uvh glibc-2.5-123.el5_11.1.i686.rpm --nodeps
reboot the system.
2015-01-28: Initial publication 2015-01-29: ScreenOS not vulnerable 2015-01-29: IDP-SA, SRC, and NSM Server & Appliance vulnerable 2015-01-29: QFabric Director and Firefly Host/vGW vulnerable but not exploitable 2015-01-29: SBR Carrier does not include glibc in the install package 2015-01-29: Clarified general mitigation 2015-01-30: Added NVD URL 2015-01-30: Included statements on JSA and STRM 2015-02-04: Added WX/WCS and Media Flow Controller 2015-02-06: JUNOSe uses glibc libraries, but may only be vulnerable via CLI 2015-02-06: Updated Space ETA 2015-02-11: Added WLAN Product Series 2015-02-12: JWAS not vulnerable. ADC and DDoS Secure under investigation. 2015-02-12: WX/WXC not vulnerable. 2015-02-13: JUNOSe not vulnerable. 2015-02-17: WLA and WLC not vulnerable. WLM and SmartPass under investigation. 2015-02-20: MFC and ADC vulnerable and resolved in software. 2015-02-23: Updated Space patch ETA to end of February. 2015-02-26: Provided pointer to Junos Space patch and provided instructions. 2015-03-10: Included solution for STRM, JSA series. 2015-03-11: Added fixed releases for CTPView and CTPOS. 2015-03-13: Added fixed releases for SRC. 2015-03-18: Added ISO and RPM fixes for NSMXpress. 2015-03-23: Clarified Junos Space patch process. 2015-04-03: WLAN products not vulnerable. 2015-04-10: Fixes for CTPOS moved to 6.6R5 and 7.0R4 due to unrelated issues with prior releases. 2015-07-14: Clarified fixupgrade.sh usage for Junos Space. 2017-03-05: Category restructure.