On SRX5000 Series devices, if ' set security zones security-zone < zone > tcp-rst ' is configured, the flowd process may crash when a specific TCP packet is received by the device and triggers a new session. The process restarts automatically. However, receipt of a constant stream of these TCP packets may result in an extended Denial of Service (DoS) condition on the device.
set security zones security-zone <
zone
> tcp-rst
This issue affects Juniper Networks Junos OS:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was found during internal product security testing or research.
This issue has been assigned CVE-2019-0064 .
The following software releases have been updated to resolve this specific issue: 18.2R3-S1, 18.4R2-S1, 18.4R3, 19.2R1-S1, 19.2R2, 19.3R1, and all subsequent releases.
This issue is being tracked as PR 1445480 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
There are no viable workarounds for this issue.
2019-10-09: Initial Publication.