Juniper JUNOS Packet Forwarding Engine IPv6 Denial of Service Vulnerability
BID:10636
Info
Juniper JUNOS Packet Forwarding Engine IPv6 Denial of Service Vulnerability
| Bugtraq ID: | 10636 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0468 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | This issue was disclosed by the vendor and CERT. |
| Vulnerable: |
Juniper JUNOS 6.3 Juniper JUNOS 6.2 Juniper JUNOS 6.1 |
| Not Vulnerable: | |
Discussion
Juniper JUNOS Packet Forwarding Engine IPv6 Denial of Service Vulnerability
Juniper routers running the JUNOS operating system are reported prone to a denial of service vulnerability due to memory exhaustion. An attacker can cause a persistent denial of service condition by repeatedly sending certain IPv6 packets to a router.
This issue affects the JUNOS Packet Forwarding Engine IPv6 branch released after February 24, 2004. All Juniper Networks M-series and T-series routing platforms with IPv6 support are also prone to this issue.
Juniper routers running the JUNOS operating system are reported prone to a denial of service vulnerability due to memory exhaustion. An attacker can cause a persistent denial of service condition by repeatedly sending certain IPv6 packets to a router.
This issue affects the JUNOS Packet Forwarding Engine IPv6 branch released after February 24, 2004. All Juniper Networks M-series and T-series routing platforms with IPv6 support are also prone to this issue.
Exploit / POC
Juniper JUNOS Packet Forwarding Engine IPv6 Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Juniper JUNOS Packet Forwarding Engine IPv6 Denial of Service Vulnerability
Solution:
Juniper Networks has reported that all JUNOS software built on or after June 21, 2004 includes the corrected code. Customers are advised to contact the vendor to obtain fixes.
Solution:
Juniper Networks has reported that all JUNOS software built on or after June 21, 2004 includes the corrected code. Customers are advised to contact the vendor to obtain fixes.
References
Juniper JUNOS Packet Forwarding Engine IPv6 Denial of Service Vulnerability
References:
References:
- Customer Support (Juniper Networks)
- Juniper Networks Information for VU#658859 (CERT)
- Vulnerability Note VU#658859 (CERT)