ISC BIND software included with Junos OS on SRX, vSRX and J-Series devices has been upgraded to resolve the following vulnerabilities:
These issues only affect devices where DNS proxy service is enabled.
DNS proxy feature is disabled by default.
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities on Juniper products.
CVE-2016-2776 has been addressed in Junos OS 12.1X46-D65, 12.3X48-D45, 15.1X49-D70, and all subsequent releases. CVE-2016-8864 has been addressed in Junos OS 12.3X48-D60, 15.1X49-D120, 17.3R2, 17.4R1 , and all subsequent releases. CVE-2016-9131, CVE-2016-9147 and CVE-2016-9444 have been addressed in Junos OS 12.1X46-D66, 12.3X48-D50, 15.1X49-D80 , and all subsequent releases. This issues are being tracked as PR 1219438, 1228678, 1245686, and 1307435, and are visible on the Customer Support website.
DNS proxy service may be disabled to workaround all these issues. You may view the status of DNS proxy service via the command:
show system services dns-proxy statistics ... DNS proxy statistics : Status : enabled ...
2017-04-12: Initial release. 2017-11-20: Separated fix for CVE-2016-8864 into its own set of fixed releases.