Juniper Steel-Belted Radius Multiple OpenSSL Vulnerabilities

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote host has an application installed that is affected by
multiple OpenSSL vulnerabilities.

Description :

The version of Juniper Steel-Belted Radius software installed on the
remote RedHat or CentOS host is affected by multiple OpenSSL
vulnerabilities :

- The SSL 3.0 implementation in OpenSSL does not properly
initialize data structures for block cipher padding,
which could allow remote attackers to obtain sensitive
information by decrypting the padding data sent by an
SSL peer. (CVE-2011-4576)

- The Server Gated Cryptography (SGC) implementation in
OpenSSL does not properly handle handshake restarts,
which could allow remote attackers to cause a denial of
service condition. (CVE-2011-4619)

See also :

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10544

Solution :

Updates are available from the vendor.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 4.3
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Misc.

Nessus Plugin ID: 70165 ()

Bugtraq ID: 51281

CVE ID: CVE-2011-4576
CVE-2011-4619