An Off-by-one Error vulnerability in the nginx [engine x] resolver as used in Juniper Networks NorthStar Controller allows an unauthenticated remote attacker who is able to forge UDP packets from the DNS server to cause a 1-byte memory overwrite, resulting in worker process crash or potentially, arbitrary code execution. nginx as used in NorthStar Controller was upgraded from 1.18.0 to 1.20.1.
This issue affects:
Juniper Networks NorthStar Controller
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during external security research.
This issue has been assigned CVE-2021-23017.
The following software releases have been updated to resolve these specific issues: 5.1.0 Service Pack 6, 6.2.2, and all subsequent releases.
Additionally, for NorthStar 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.2.0, 6.2.1, customers may install security patch NorthStar_6.x.x-Patch-SECURITY-nginx1.20.1-20220131_221547-8450ce7_14.x86_64.rpm to resolve this specific issue.
This issue is being tracked as 1644981.Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).