FYI…

Juniper Networks - GNU Bash Shell multiple vulns…
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648
"Product Affected:
Junos Space and JA1500, JA2500 (Junos Space Appliance), STRM and JSA series, NSM Appliances (NSM3000 and NSMExpress), IDP Series, Junos Content Encore (Media Flow Controller) prior to 12.3.8.
Problem: Bash or the Bourne again shell has vulnerabilities in the way it handles environment variables when it is invoked. Under some scenarios, network based remote attackers can inject shell script that can be executed on a system. This is also known as "ShellShock".
These issues have been assigned CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE-2014-6278.
Products vulnerable to remote exploitation risks: (See list at the juniper URL above.)
Modification History:
Sep 25, 2014: Initial release.
Sep 26, 2014: Provided solution for JSA/STRM Series, updated the status of NSM to be vulnerable, provided workaround for NSM, included statement on SRC series.
Sep 29, 2014: Updated the status of SSL VPN products as vulnerable to lesser security risks, updated the list of known CVEs related to shellshock issue.
Sep 30, 2014: Provided solution for NSM Appliances and Junos Space.
Oct 1, 2014: Provided final solution for JSA/STRM Series and solution for IDP Series.
Oct 2, 2014: Added statement about WLC series which is not affected, updated the status of Junos Content Encore (MFC) as vulnerable to remote exploitation risks.
Oct 3, 2014: Provided final solution for Junos Content Encore (MFC).
Oct 6, 2014: Provided a solution for NSM CentOS 4 based installations.
 

:ph34r: :ph34r: