Multiple vulnerabilities in stunnel software included with Junos OS have been resolved by upgrading stunnel to 5.38.
Stunnel is used for providing SSL/TLS protection to Junos XML protocol server (xnm-ssl). These issues only affect devices where xnm-ssl is configured.
Affected releases are Juniper Networks Junos OS:
Important vulnerabilities resolved in stunnel 5.38 include:
Stunnel software included with Junos OS 12.1X46, 12.3X48 has been upgraded from 4.04 to 5.38 in 12.1X46-D76, 12.3X48-D50 and subsequent releases.
Stunnel software in Junos 15.1 and above has been upgraded from 5.01 to 5.38. This resolves CVE-2013-1762, CVE-2014-0016 and CVE-2015-3644.
The following software releases have been updated to resolve this specific issue: 12.1X46-D76, 12.3X48-D50, 15.1R7, 15.1X49-D100, 16.1R5, 16.2R2, 17.1R2, 17.2R1, and all subsequent releases.
Upgraded stunnel software includes the fixes for CVE-2015-3644, CVE-2013-1762, CVE-2008-2400, however these issues do not affect or impact Junos OS.
These issues are being tracked as PR 1226804 and 31143 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
Limit access to the administrative interfaces such as xnm-ssl on the device to only trusted networks and hosts.
Disable xnm-ssl if Junos XML access to the device is not required or being used