|
Check Point Firewall-1 NG SmartDefense RFC2397 Bypass Weakness
|
|
Secunia Advisory:
|
SA13792
|
|
|
Release Date:
|
2005-01-13
|
|
Last Update:
|
2005-01-17
|
|
Popularity:
|
17,152 views
|
|
|
Critical:
|
 Not critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Workaround
|
|
| Software: | Check Point VPN-1/FireWall-1 NG with Application Intelligence (AI)
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: A weakness has been reported in Check Point Firewall-1 NG with SmartDefense, which allows malware to bypass detection.
The weakness is caused due to a lack of RFC2397 support. This can be exploited to bypass the malware detection by sending malicious image files, which are base64 encoded and embedded in an HTML file according to the standard specified in RFC2397, which is supported by a number of client applications capable of rendering HTML files (e.g. email clients and browsers).
A PoC has been published, which embeds an image that attempts to exploit the GDI+ JPEG parsing vulnerability in Microsoft Windows.
NOTE: Content inspection software can generally be bypassed in many ways by obfuscating data and exploit code. However, this advisory describes lack of compliance with a widely deployed standard for embedding pictures in HTML files.
This has been reported to affect Check Point Firewall-1 NG R55 HFA08 with SmartDefense 541041226. Other versions may also be vulnerable.
Solution: The vendor recommends using the newly added option to block encoded images: "Enable Block Encoded images". Note: This may impact the functionality of some websites and emails.
Do not rely solely on gateway / perimeter security.
Apply patches to fix vulnerabilities in client software and apply other defence in depth measures.
Provided and/or discovered by: Darren Bounds, Intrusense.
Changelog: 2005-01-17: Updated solution.
Original Advisory: http://www.intrusense.com/av-bypass/image-bypass-advisory.txt
Other References: SA12528:
http://secunia.com/advisories/12528/
RFC2397:
http://www.ietf.org/rfc/rfc2397.txt
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|