Release date:
Updated on:
Affected Systems:
Juniper Networks JUNOS 12.1X45-D10
Juniper Networks JUNOS 12.1X44-D20
Juniper Networks junoperating 12.1X44
Juniper Networks JUNOS 12.1R7
Juniper Networks JUNOS 11.4R8
Juniper Networks JUNOS 10.4R16
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64766
CVE (CAN) ID: CVE-2014-0616
Junos is an application development platform or network operating system used in the Juniper Networks hardware system.
When Juniper Junos processes a large UPDATE, BGP immediately sends an undo message, and the rpd of the route background program may crash, resulting in DOS.
<* Source: vendor
Link: http://kb.juniper.net/InfoCenter/index? Page = content & id = JSA10609
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Juniper Networks
----------------
Juniper Networks has released a Security Bulletin (JSA10609) for this purpose and corresponding patches:
JSA10609: Junos: rpd crash when attempting to send an oversized bgp update (CVE-2014-0616)
Link: http://kb.juniper.net/InfoCenter/index? Page = content & id = JSA10609