Multiple vulnerabilities in OpenLDAP have been resolved in the Juniper Networks Steel-Belted Radius (SBR) Carrier AAA (Authentication, Authorization, and Accounting) server on 64-bit Solaris by upgrading OpenLDAP from version 2.4.50 to 2.4.58 for 64-bit Solaris alone.
These issues affect all versions of Juniper Networks SBR Carrier prior to 8.6.0R15 on 64-bit Solaris.
These issues are not applicable to 32-bit Solaris.
These issues are not applicable to any Linux versions of SBR Carrier.
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: 64-bit Solaris 8.6.0R15, and all subsequent releases.
These issues are being tracked as 1613549 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/ .
2022-01-12: Initial Publication.