Product Affected

These issues affect all versions of Junos OS Evolved before 22.3R3-S2-EVO, 22.4-EVO.
High
CVSS 3.1: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 4.0: 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem

Multiple vulnerabilities are resolved in libslax 0.22.1. 

These issues affect Juniper Networks Junos OS Evolved:
  • All versions before 22.3R3-S2-EVO
  • from 22.4 before 22.4R2-EVO. 
Important security issues resolved are described below:
CVECVSSSummary
CVE-2021-395318.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow.
CVE-2021-395338.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow.
CVE-2021-395348.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)An issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow.

Solution

The following software releases have been updated to resolve these specific issues: 

Junos OS Evolved: 22.3R3-S2-EVO, 22.4R2-EVO, 22.4R3-EVO, 23.2R1-EVO, and all subsequent releases.
 

These issues are being tracked as 1698495 which are visible on the Customer Support website.
 

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for these issues.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

  • 2024-04-10 - Initial Publication
  • 2024-09-13: Minor formatting change to CVSS field

Related Information