iTnews Asia
  • Home
  • News
  • Security

Juniper Networks battles swarm of bugs

Juniper Networks battles swarm of bugs

Catches up with huge number of third-party vulnerabilities.

By Richard Chirgwin on Jul 18, 2022 11:39AM

Juniper Networks has gone public with a number of vulnerabilities serious enough to attract the attention of America’s Cybersecurity and Infrastructure Security Agency.

Of the 30 vulnerabilities disclosed this week, four are rated as critical and eight are rated as high severity.

The critical vulnerabilities affect the company’s Junos Space, Contrail Networking, and Northstar Controller products.

This critical bulletin covers multiple vulnerabilities in third-party products shipped with Junos Space versions prior to 22.1R1. 

Affected third-party products include the nginx resolver, Oracle Java SE, OpenSSH, Samba, the RPM package manager, Kerberos, OpenSSL, the Linux kernel, curl, and MySQL Server.

Juniper Networks Contrail Networking needs to be upgraded to release 21.4.0 to fix the Red Hat Universal Base Image (UBI) container image from Red Hat Enterprise Linux 7 to Red Hat Enterprise Linux 8, taking care of 23 vulnerabilities stretching back to 2013.

In another fix for third-party components, the Junos Space Security Director Policy Enforcer has been upgraded to use CentOS 7.9, in version 22.1R1.

In CVE-2021-23017, the nginx load balancer Juniper ships with its Northstar Controller has a remote code execution bug.

“An Off-by-one Error vulnerability in the nginx resolver … allows an unauthenticated remote attacker who is able to forge UDP packets from the DNS server to cause a 1-byte memory overwrite, resulting in worker process crash or potentially, arbitrary code execution,” the advisory states.

This vulnerability is patched in version 1.20.1 of the Northstar Controller.

A number of high-severity bugs are also disclosed in Junos OS. The full list of vulnerabilities can be found here. 

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
contrail juniper networks junos networking patch security security vulnerability

Related Articles

  • Your organisation’s physical security can be a gateway for cybercriminals
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Your organisation’s physical security can be a gateway for cybercriminals

Your organisation’s physical security can be a gateway for cybercriminals

The best way to outsmart your threat actors is to think like one

The best way to outsmart your threat actors is to think like one

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Perkeso ramps up security measures after cyber attack

Malaysia's Perkeso ramps up security measures after cyber attack

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.