PT-2019-1967 · Juniper Networks · Junos

Published

2019-04-10

·

Updated

2021-10-25

·

CVE-2019-0008

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Junos OS versions 14.1X53; 15.1X53 prior to 15.1X53-D235; 17.1 prior to 17.1R3; 17.2 prior to 17.2R3; 17.3 prior to 17.3R3-S2, 17.3R4; 17.4 prior to 17.4R2-S1, 17.4R3; 18.1 prior to 18.1R3-S1, 18.1R4; 18.2 prior to 18.2R2; 18.2X75 prior to 18.2X75-D30; 18.3 prior to 18.3R2
Description The issue is caused by a buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process. This can be triggered by a certain sequence of valid BGP or IPv6 BFD packets, potentially leading to a crash of the fxpc daemon or remote code execution.
Recommendations For versions 14.1X53, update to a version after 14.1X53. For versions 15.1X53, update to 15.1X53-D235 or later. For versions 17.1, update to 17.1R3 or later. For versions 17.2, update to 17.2R3 or later. For versions 17.3, update to 17.3R3-S2, 17.3R4 or later. For versions 17.4, update to 17.4R2-S1, 17.4R3 or later. For versions 18.1, update to 18.1R3-S1, 18.1R4 or later. For versions 18.2, update to 18.2R2 or later. For versions 18.2X75, update to 18.2X75-D30 or later. For versions 18.3, update to 18.3R2 or later.

Fix

RCE

Stack Overflow

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01657
CVE-2019-0008

Affected Products

Junos