|
Check Point Firewall-1 NG SmartDefense RFC2397 Bypass Weakness
|
|
|
|
|
Secunia Advisory:
|
SA13792
|
|
|
Release Date:
|
2005-01-13
|
|
Last Update:
|
2005-01-17
|
|
|
Critical:
|

Not critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Workaround
|
|
| Software: | Check Point VPN-1/FireWall-1 NG with Application Intelligence (AI)
|
|
|
|
|
|
Description: A weakness has been reported in Check Point Firewall-1 NG with SmartDefense, which allows malware to bypass detection.
The weakness is caused due to a lack of RFC2397 support. This can be exploited to bypass the malware detection by sending malicious image files, which are base64 encoded and embedded in an HTML file according to the standard specified in RFC2397, which is supported by a number of client applications capable of rendering HTML files (e.g. email clients and browsers).
A PoC has been published, which embeds an image that attempts to exploit the GDI+ JPEG parsing vulnerability in Microsoft Windows.
NOTE: Content inspection software can generally be bypassed in many ways by obfuscating data and exploit code. However, this advisory describes lack of compliance with a widely deployed standard for embedding pictures in HTML files.
This has been reported to affect Check Point Firewall-1 NG R55 HFA08 with SmartDefense 541041226. Other versions may also be vulnerable.
Solution: The vendor recommends using the newly added option to block encoded images: "Enable Block Encoded images". Note: This may impact the functionality of some websites and emails.
Do not rely solely on gateway / perimeter security.
Apply patches to fix vulnerabilities in client software and apply other defence in depth measures.
Provided and/or discovered by: Darren Bounds, Intrusense.
Changelog: 2005-01-17: Updated solution.
Original Advisory: http://www.intrusense.com/av-bypass/image-bypass-advisory.txt
Other References: SA12528:
http://secunia.com/advisories/12528/
RFC2397:
http://www.ietf.org/rfc/rfc2397.txt
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
9 Related Secunia Security Advisories
|
|
|
1. CheckPoint VPN-1 IP Address Collision Security Issue
|
|
2. Check Point VPN/Firewall Directory Traversal Vulnerability
|
|
3. Check Point Firewall/VPN ISAKMP IKE Message Processing Denial of Service
|
|
4. Check Point Firewall CIFS Service Group Rule Bypass
|
|
5. Check Point VPN-1 ASN.1 Decoding Heap Overflow Vulnerability
|
|
6. Check Point VPN-1 Products ISAKMP Buffer Overflow Vulnerability
|
|
7. Check Point Products OpenSSL Vulnerabilities
|
|
8. Check Point FireWall-1 HTTP Parsing Format String Vulnerabilities
|
|
9. Check Point FireWall-1 H.323 Protocol Implementation Vulnerabilities
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|