Multiple vulnerabilities have been resolved in Steel Belted Radius Carrier Edition by updating third party software included with Steel Belted Radius Carrier Edition or by fixing vulnerabilities found during internal testing.
These issues potentially affect Steel Belted Radius Carrier Edition:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities. These issues were discovered during external security research.
Important security issues resolved include:
These issues are resolved in Steel Belted Radius Carrier Edition 8.4R14 on RHEL6 (32-bit), RHEL6 (64-bit), RHEL7, Sparc Solaris (32-bit), Sparc Solaris (64-bit) and 8.5R5 on RHEL6 (64-bit), RHEL7, Sparc Solaris (64-bit) and all subsequent releases. These issues are being tracked as PR 1397207 , 1397301 and 1397304 which are visible on the Customer Support website. Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
There are no known workarounds for these issues.
2019-07-10: Initial Publication