PT-2019-1967 · Juniper Networks · Junos
Published
2019-04-10
·
Updated
2021-10-25
·
CVE-2019-0008
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS versions 14.1X53; 15.1X53 prior to 15.1X53-D235; 17.1 prior to 17.1R3; 17.2 prior to 17.2R3; 17.3 prior to 17.3R3-S2, 17.3R4; 17.4 prior to 17.4R2-S1, 17.4R3; 18.1 prior to 18.1R3-S1, 18.1R4; 18.2 prior to 18.2R2; 18.2X75 prior to 18.2X75-D30; 18.3 prior to 18.3R2
Description
The issue is caused by a buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process. This can be triggered by a certain sequence of valid BGP or IPv6 BFD packets, potentially leading to a crash of the fxpc daemon or remote code execution.
Recommendations
For versions 14.1X53, update to a version after 14.1X53.
For versions 15.1X53, update to 15.1X53-D235 or later.
For versions 17.1, update to 17.1R3 or later.
For versions 17.2, update to 17.2R3 or later.
For versions 17.3, update to 17.3R3-S2, 17.3R4 or later.
For versions 17.4, update to 17.4R2-S1, 17.4R3 or later.
For versions 18.1, update to 18.1R3-S1, 18.1R4 or later.
For versions 18.2, update to 18.2R2 or later.
For versions 18.2X75, update to 18.2X75-D30 or later.
For versions 18.3, update to 18.3R2 or later.
Fix
RCE
Stack Overflow
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos