Multiple vulnerabilities in SQLite as used in Juniper Networks Junos OS and Junos OS Evolved have been resolved by upgrading SQLite from 3.31.1 to 3.37.0.
Services that rely upon SQLite are the Connectivity Fault Management (CFM) Daemon (CFDM), AppID, IDP, Apache2, J-Web, and JSQL as used by IPID, SecIntel Threat Intelligence, useridd, accounts, processes and services.
These services are all exposed to potentially exploitable Denial of Service (DoS) attacks which may be exploited by a remote unauthenticated attacker sending packets to the device.
An attacker may be able to sustain the Denial of Service (DoS) condition by sending subsequent packets.
These issues affect:
Juniper Networks Junos OS
These issues are not applicable to versions prior to 15.1X49-D100.
Juniper Networks Junos OS Evolved
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
Note: An assessment was completed as listed in the 3.37.1 vs 3.37.2 change log for the lang_upsert incorrect byte-code leading to NULL-pointer dereference and the FTS5 OOB read related to reading corrupt database file and Junos OS and Junos OS Evolved are not affected by these noted issues.
Note: CVE-2021-36690: This bug is not in the SQLite core library, but rather in an experimental extension that is used to implement the .expert command in the CLI. The code that contains the bug does not appear in standard SQLite builds, though it is included in the sqlite3.exe command-line tool. Applications must link against the extra source code files that implement the extension and take other deliberate actions to activate the extension before the troublesome code can be run. For the rare application that uses the troublesome extension, the consequence of this bug is that malicious SQL can cause a NULL pointer deference and denial of service.
Note: CVE-2020-11656: This issue requires compilation of SQLite with debug mode enabled. Juniper Networks does not enable SQLite debug mode.
Important security issues resolved include:
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).These issues are being tracked as 1583420.