CVE-2018-0061
published 2018-10-10CVE-2018-0061: A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect system…
PriorityP431medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
2.27%
81.2th percentile
A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect system performance. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D81 on SRX Series; 12.3 versions prior to 12.3R12-S11; 12.3X48 versions prior to 12.3X48-D80 on SRX Series; 15.1 versions prior to 15.1R7; 15.1X49 versions prior to 15.1X49-D150, 15.1X49-D160 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D68 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D235 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D495 on NFX Series; 16.1 versions prior to 16.1R4-S12, 16.1R6-S6, 16.1R7; 16.2 versions prior to 16.2R2-S7, 16.2R3; 17.1 versions prior to 17.1R2-S9, 17.1R3; 17.2 versions prior to 17.2R2-S6, 17.2R3; 17.2X75 versions prior to 17.2X75-D100; 17.3 versions prior to 17.3R2-S4, 17.3R3; 17.4 versions prior to 17.4R1-S5, 17.4R2; 18.2X75 versions prior to 18.2X75-D5.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | qfx_series | — | — |
| juniper | srx_series | — | — |
| juniper_networks | junos_os | >= 12.1X46 < 12.1X46-D81 | 12.1X46-D81 |
| juniper_networks | junos_os | >= 12.3 < 12.3R12-S11 | 12.3R12-S11 |
| juniper_networks | junos_os | >= 12.3X48 < 12.3X48-D80 | 12.3X48-D80 |
| juniper_networks | junos_os | >= 15.1 < 15.1R7 | 15.1R7 |
| juniper_networks | junos_os | >= 15.1X49 < 15.1X49-D150, 15.1X49-D160 | 15.1X49-D150, 15.1X49-D160 |
| juniper_networks | junos_os | >= 15.1X53 < 15.1X53-D59 | 15.1X53-D59 |
| juniper_networks | junos_os | >= 15.1X53 < 15.1X53-D68 | 15.1X53-D68 |
| juniper_networks | junos_os | >= 15.1X53 < 15.1X53-D235 | 15.1X53-D235 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2018-0061: A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect syst
vendor_juniper·2018-10-10·CVSS 5.3
CVE-2018-0061 [MEDIUM] CWE-400 CVE-2018-0061: A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect syst
CVE-2018-0061: A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect system performance. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D81 on SRX Series; 12.3 versions prior to 12.3R12-S11; 12.3X48 versions prior to 12.3X48-D80 on SRX Series; 15.1 versions prior to 15.1R7; 15.1X49 versions prior to 15.1X49-D150, 15.1X49-D160 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D68 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D235 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D495 on NFX Series; 16.1 versions prior to 16.1R4-S12, 16.1R6-S6, 16.1R7; 16.2 versions prior to 16.2R2-S7, 16
GHSA
GHSA-mg2c-wjpf-6pjp: A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect syst
ghsa_unreviewed·2022-05-13
CVE-2018-0061 [MEDIUM] CWE-400 GHSA-mg2c-wjpf-6pjp: A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect syst
A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect system performance. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D81 on SRX Series; 12.3 versions prior to 12.3R12-S11; 12.3X48 versions prior to 12.3X48-D80 on SRX Series; 15.1 versions prior to 15.1R7; 15.1X49 versions prior to 15.1X49-D150, 15.1X49-D160 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D68 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D235 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D495 on NFX Series; 16.1 versions prior to 16.1R4-S12, 16.1R6-S6, 16.1R7; 16.2 versions prior to 16.2R2-S7, 16.2R3; 17.1 vers
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7846 Mozilla: JavaScript Execution via RSS in mailbox:// origin
bugzilla·2018-01-02·CVSS 5.3
CVE-2017-7846 [MEDIUM] CVE-2017-7846 Mozilla: JavaScript Execution via RSS in mailbox:// origin
CVE-2017-7846 Mozilla: JavaScript Execution via RSS in mailbox:// origin
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via “View -> Feed article -> Website” or in the standard format of “View -> Feed article -> default format”.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: cure53
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/#CVE-2017-7829
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0061 https://access.redhat.com/errata/RHSA-2018:0061
Bugzilla
CVE-2017-7829 Mozilla: From address with encoded null character is cut off in message header display
bugzilla·2018-01-02·CVSS 5.3
CVE-2017-7829 [MEDIUM] CVE-2017-7829 Mozilla: From address with encoded null character is cut off in message header display
CVE-2017-7829 Mozilla: From address with encoded null character is cut off in message header display
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Sabri Haddouche
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/#CVE-2017-7829
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0061 https://access.redhat.com/errata/RHSA-2018:0061
Bugzilla
CVE-2017-7848 Mozilla: RSS Feed vulnerable to new line Injection
bugzilla·2018-01-02·CVSS 5.3
CVE-2017-7848 [MEDIUM] CVE-2017-7848 Mozilla: RSS Feed vulnerable to new line Injection
CVE-2017-7848 Mozilla: RSS Feed vulnerable to new line Injection
RSS fields can inject new lines into the created email structure, modifying the message body.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: cure53
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/#CVE-2017-7848
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0061 https://access.redhat.com/errata/RHSA-2018:0061
Bugzilla
CVE-2017-7847 Mozilla: Local path string can be leaked from RSS feed
bugzilla·2018-01-02·CVSS 4.3
CVE-2017-7847 [MEDIUM] CVE-2017-7847 Mozilla: Local path string can be leaked from RSS feed
CVE-2017-7847 Mozilla: Local path string can be leaked from RSS feed
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: cure53
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/#CVE-2017-7847
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0061 https://access.redhat.com/errata/RHSA-2018:0061
2018-10-10
Published