Junos RDP Crash Vulnerability

Summary
RDP crash when receiving BGP UPDATE with malformed inetflow prefix.
Impact
After trying to exceed the process memory limit, RPD will crash and restart. The system recovers after the crash, however a constant stream of malformed updates could cause an extended outage.
Solution
New builds of Junos OS software are available from Juniper. As a workaround disable the propagation of flow-specification NLRI messages via BGP by removing the flow configuration option from protocols bgp ... family inet.
Insight
Receipt of a BGP UPDATE message containing a crafted flow specification NLRI may cause RPD to crash. The update creates an invalid inetflow prefix which causes the RPD process to allocate memory until it reaches its assigned memory limit.
Affected
Junos OS 10.0, 10.4, 11.4, 12.1 and 12.2.
Detection
Check the OS build.
References

Updated on 2015-03-25