Receipt of a specific packet on the out-of-band management interface fxp0 may cause the system to crash and restart (vmcore). By continuously sending a specially crafted packet to the fxp0 interface, an attacker can repetitively crash the rpd process causing prolonged Denial of Service (DoS). Affected releases are Juniper Networks SRX5000 Series: 12.1X46 versions prior to 12.1X46-D82; 12.3X48 versions prior to 12.3X48-D80; 15.1X49 versions prior to 15.1X49-D160.
Solution:
Workaround:
The product does not release or incorrectly releases a resource before it is made available for re-use.
Link | Tags |
---|---|
https://kb.juniper.net/JSA10936 | patch vendor advisory |
http://www.securityfocus.com/bid/107872 | vdb entry broken link |