Junos OS: jdhcpd crash upon receipt of crafted DHCPv6 solicit message
Published Apr 10, 2019
7.5
HIGHCVSS 3.1
EPSS 1.27%
Description
In a Dynamic Host Configuration Protocol version 6 (DHCPv6) environment, the jdhcpd daemon may crash and restart upon receipt of certain DHCPv6 solicit messages received from a DHCPv6 client. By continuously sending the same crafted packet, an attacker can repeatedly crash the jdhcpd process causing a sustained Denial of Service (DoS) to both IPv4 and IPv6 clients. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S12, 15.1R7-S3; 15.1X49 versions prior to 15.1X49-D171, 15.1X49-D180; 15.1X53 versions prior to 15.1X53-D236, 15.1X53-D496; 16.1 versions prior to 16.1R3-S10, 16.1R7-S4; 16.2 versions prior to 16.2R2-S8; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R3-S1; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S6, 17.4R2-S3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S2; 18.2 versions prior to 18.2R2; 18.2X75 versions prior to 18.2X75-D30; 18.3 versions prior to 18.3R1-S2. This issue does not affect Junos OS releases prior to 15.1.
Affected products
-
- Version 15.1StatusaffectedConstraints<15.1F6-S12, 15.1R7-S3
- Version 15.1X49StatusaffectedConstraints<15.1X49-D171, 15.1X49-D180
- Version 15.1X53StatusaffectedConstraints<15.1X53-D236, 15.1X53-D496
- Version 16.1StatusaffectedConstraints<16.1R3-S10, 16.1R7-S4
- Version 16.2StatusaffectedConstraints<16.2R2-S8
- Version 17.1StatusaffectedConstraints<17.1R2-S10, 17.1R3
- Version 17.2StatusaffectedConstraints<17.2R1-S8, 17.2R3-S1
- Version 17.3StatusaffectedConstraints<17.3R3-S3
- Version 17.4StatusaffectedConstraints<17.4R1-S6, 17.4R2-S3
- Version 18.1StatusaffectedConstraints<18.1R2-S4, 18.1R3-S2
- Version 18.2StatusaffectedConstraints<18.2R2
- Version 18.2X75StatusaffectedConstraints<18.2X75-D30
- Version 18.3StatusaffectedConstraints<18.3R1-S2
- Version allStatusunaffectedConstraints<15.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | n/a |
|
Configuration 1
Configuration 2
Configuration 3
Configuration 4
Configuration 10
Configuration 12
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: Junos OS 15.1F6-S12, 15.1R7-S3, 15.1X49-D171, 15.1X49-D180, 15.1X53-D236, 15.1X53-D496, 16.1R3-S10, 16.1R7-S4, 16.2R2-S8, 17.1R2-S10, 17.1R3, 17.2R1-S8, 17.2R3-S1, 17.3R3-S3, 17.4R1-S6, 17.4R2-S3, 18.1R2-S4, 18.1R3-S2, 18.2R2, 18.2X75-D30, 18.3R1-S2, 18.4R1, and all subsequent releases.
No CWE recorded.
References (2)
- http://www.securityfocus.com/bid/107894 vdb-entryx_refsource_BIDBroken Link
- https://kb.juniper.net/JSA10926 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/107894 | vdb-entryx_refsource_BIDBroken Link | |
| https://kb.juniper.net/JSA10926 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.