Product Affected

These issues affect all versions of Contrail Networking.
High
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Problem

Multiple vulnerabilities in third party software used in Juniper Networks Contrail Networking have been resolved in release 21.3.
 

These issue was discovered during external security research.
 

Important security issues resolved include:

CVECVSSSummary
CVE-2019-13499.3 AV:N/AC:M/Au:N/C:C/I:C/A:CA remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
CVE-2015-83919.0 (AV:N/AC:L/Au:N/C:P/I:P/A:C)The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
CVE-2014-94717.5 AV:N/AC:L/Au:N/C:P/I:P/A:PThe parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.

 

Solution

The following software releases have been updated to resolve these specific issues: Contrail Networking 21.3 and all subsequent releases.
 

These issues are being tracked as CEM-21367 and CEM-22413.
 

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
 

Implementation

Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.

Workaround

There are no known workarounds for these issues.
 

However, risk of malicious exploitation may be mitigated by limiting the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the device only from trusted, administrative networks or hosts.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2022-04-13: Initial Publication.

Related Information