Multiple vulnerabilities have been resolved in Junos Space 16.1R1 release. Third party software packages that have been upgraded to resolve vulnerabilities in prior releases include:
Important security issues resolved as a result of these upgrades include,
Please refer to JSA10759 [juniper.net] for a list of OpenSSL vulnerabilities resolved as a result of upgrading it to 1.0.1t.
Apart of the above issues, Junos Space 16.1R1 also resolves the following issues found during internal product testing:
In addition to the above, Junos Space release 16.1R1 contains many security improvements and security feature enhancements. Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues have been resolved in Junos Space 16.1R1 and all subsequent releases. These issues are being tracked as PRs 1051210, 1097316, 1082037, 1107640, 1136574, 1201531, 1206933, 1214374, 1214763, 1215142, 1226553, 1231941,1232770, 1235133, 882239, 975417, 975435, 975452, 975458, 975482, 975495, 983913, 983914, 983940, and 983966, and are visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
2017-01-11: Initial publication 2018-01-02: Added PR 1231941 reflecting CVE IDs: CVE-2013-2566 , CVE-2015-4000 and CVE-2016-2183. PR 1097316 reflecting CVE IDs: CVE-2005-1730 , CVE-2009-5111 , CVE-2007-6750 and CVE-2012-5568 . 2018-08-22: Added PR 1051210 reflecting CVE IDs: CVE-2014-1568 CVE-2013-6435 CVE-2016-9147 and CVE-2012-4244