Juniper Junos BGP UPDATE Processing Flaw Lets Remote Users Cause the Target RPD Service to Crash
|
SecurityTracker Alert ID: 1038257 |
SecurityTracker URL: http://securitytracker.com/id/1038257
|
CVE Reference:
CVE-2017-2313
(Links to External Site)
|
Date: Apr 13 2017
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in Juniper Junos. A remote user can cause the target service to crash.
A remote user can send a specially crafted BGP UPDATE packet to cause the target routing processing daemon (rpd) to crash and restart.
Systems with BGP enabled are affected.
The vendor has assigned PR 1229868 to this vulnerability.
|
Impact:
A remote user can cause the target service to crash.
|
Solution:
The vendor has issued a fix (15.1F2-S15, 15.1F5-S7, 15.1F6-S5, 15.1F7, 15.1R4-S7, 15.1R5-S2, 15.1R6, 15.1X49-D78, 15.1X49-D80, 15.1X53-D230, 15.1X53-D63, 15.1X53-D70, 16.1R3-S3, 16.1R4, 16.2R1-S3, 16.2R2, 17.1R1, 17.2R1).
The vendor advisory is available at:
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10778
|
Vendor URL: kb.juniper.net/InfoCenter/index?page=content&id=JSA10778 (Links to External Site)
|
Cause:
State error
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|