Juniper Junos OS update for bind



Published: 2021-01-14
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2020-8617
CWE-ID CWE-617
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Subscribe
Juniper Junos OS
Operating systems & Components / Operating system

Vendor Juniper Networks, Inc.

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Reachable Assertion

EUVDB-ID: #VU28123

Risk: Medium

CVSSv3.1: 7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C]

CVE-ID: CVE-2020-8617

CWE-ID: CWE-617 - Reachable Assertion

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion when checking validity of messages containing TSIG resource records within tsig.c. A remote attacker can send a specially crafted message and cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server.

Mitigation

Install updates from vendor's website.

This issue affects Juniper Networks Junos OS on SRX Series:

  • 12.3X48 versions prior to 12.3X48-D105;
  • 15.1X49 versions prior to 15.1X49-D230;
  • 17.3 versions prior to 17.3R3-S10;
  • 17.4 versions prior to 17.4R2-S12, 17.4R3-S4;
  • 18.1 versions prior to 18.1R3-S12;
  • 18.2 versions prior to 18.2R2-S8, 18.2R3-S6;
  • 18.3 versions prior to 18.3R3-S4;
  • 18.4 versions prior to 18.4R1-S8, 18.4R2-S7, 18.4R3-S6;
  • 19.1 versions prior to 19.1R1-S6, 19.1R3-S3;
  • 19.2 versions prior to 19.2R1-S6, 19.2R3;
  • 19.3 versions prior to 19.3R2-S5, 19.3R3;
  • 19.4 versions prior to 19.4R2-S2, 19.4R3;
  • 20.1 versions prior to 20.1R2;
  • 20.2 versions prior to 20.2R1-S2, 20.2R2.

Vulnerable software versions

Juniper Junos OS: 12.3x48 - 20.3

External links

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA11091&cat=SIRT_1&actp=LIST


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, a fully functional exploit for this vulnerability is available.



###SIDEBAR###