Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability
BID:26869
Info
Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability
| Bugtraq ID: | 26869 |
| Class: | Design Error |
| CVE: |
CVE-2007-6372 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2007 12:00AM |
| Updated: | May 05 2008 01:46PM |
| Credit: | This issue was discussed on the Juniper for Network Service Providers list by a variety of sources. |
| Vulnerable: |
Juniper JUNOS 8.4 Juniper JUNOS 7.3 |
| Not Vulnerable: |
Juniper JUNOS 8.5.R1 |
Discussion
Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability
JUNOS is prone to a remote denial-of-service vulnerability that arises when the application handles specially crafted BGP packets.
Versions of JUNOS from 7.3 to 8.4 are reported vulnerable.
NOTE: Multiple sources report that upgrading to JUNOS 8.5R1 or above will solve this issue, but this could not be confirmed at the time of writing.
JUNOS is prone to a remote denial-of-service vulnerability that arises when the application handles specially crafted BGP packets.
Versions of JUNOS from 7.3 to 8.4 are reported vulnerable.
NOTE: Multiple sources report that upgrading to JUNOS 8.5R1 or above will solve this issue, but this could not be confirmed at the time of writing.
Exploit / POC
Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability
Solution:
The vendor has reportedly corrected this issue in JUNOS 8.5R1 and higher. We have been unable to confirm this. Please contact the vendor for more information and to obtain fixes.
Solution:
The vendor has reportedly corrected this issue in JUNOS 8.5R1 and higher. We have been unable to confirm this. Please contact the vendor for more information and to obtain fixes.
References
Juniper Networks JUNOS Malformed BGP Remote Denial of Service Vulnerability
References:
References:
- Juniper Networks Homepage (Juniper Networks)
- Vulnerability Note VU#929656 Multiple vendors' BGP implementations do not proper (US-CERT)