SB2020010337 - Memory leak in Junos OS RE when handling IPv6 packets
Published: January 3, 2020 Updated: October 26, 2023
Security Bulletin ID
SB2020010337
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2020-1603)
The vulnerability allows a remote non-authenticated attacker to a crash the entire system.
Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE.
Remediation
Install update from vendor's website.