Juniper Junos FreeBSD libc db Information Disclosure (JSA10756)
Medium Nessus Plugin ID 92514
SynopsisThe remote device is missing a vendor-supplied security patch.
DescriptionAccording to its self-reported version number, the remote Juniper Junos device is affected by an information disclosure vulnerability in the underlying FreeBSD operating system libc db interface due to improper initialization of memory for Berkeley DB 1.85 database structures. A local attacker can exploit this to disclose sensitive information by reading a database file.
SolutionUpgrade to the relevant Junos software release referenced in Juniper advisory JSA10756.