Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Check Point Firewall-1 NG SmartDefense RFC2397 Bypass Weakness Advisory Available in Danish 

Secunia Advisory: SA13792  
Release Date: 2005-01-13
Last Update: 2005-01-17

Critical:
Not critical
Impact: Security Bypass
Where: From remote
Solution Status: Vendor Workaround

Software:Check Point VPN-1/FireWall-1 NG with Application Intelligence (AI)



Description:
A weakness has been reported in Check Point Firewall-1 NG with SmartDefense, which allows malware to bypass detection.

The weakness is caused due to a lack of RFC2397 support. This can be exploited to bypass the malware detection by sending malicious image files, which are base64 encoded and embedded in an HTML file according to the standard specified in RFC2397, which is supported by a number of client applications capable of rendering HTML files (e.g. email clients and browsers).

A PoC has been published, which embeds an image that attempts to exploit the GDI+ JPEG parsing vulnerability in Microsoft Windows.

NOTE: Content inspection software can generally be bypassed in many ways by obfuscating data and exploit code. However, this advisory describes lack of compliance with a widely deployed standard for embedding pictures in HTML files.

This has been reported to affect Check Point Firewall-1 NG R55 HFA08 with SmartDefense 541041226. Other versions may also be vulnerable.

Solution:
The vendor recommends using the newly added option to block encoded images: "Enable Block Encoded images". Note: This may impact the functionality of some websites and emails.

Do not rely solely on gateway / perimeter security.

Apply patches to fix vulnerabilities in client software and apply other defence in depth measures.

Provided and/or discovered by:
Darren Bounds, Intrusense.

Changelog:
2005-01-17: Updated solution.

Original Advisory:
http://www.intrusense.com/av-bypass/image-bypass-advisory.txt

Other References:
SA12528:
http://secunia.com/advisories/12528/

RFC2397:
http://www.ietf.org/rfc/rfc2397.txt



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

9 Related Secunia Security Advisories

1. CheckPoint VPN-1 IP Address Collision Security Issue
2. Check Point VPN/Firewall Directory Traversal Vulnerability
3. Check Point Firewall/VPN ISAKMP IKE Message Processing Denial of Service
4. Check Point Firewall CIFS Service Group Rule Bypass
5. Check Point VPN-1 ASN.1 Decoding Heap Overflow Vulnerability
6. Check Point VPN-1 Products ISAKMP Buffer Overflow Vulnerability
7. Check Point Products OpenSSL Vulnerabilities
8. Check Point FireWall-1 HTTP Parsing Format String Vulnerabilities
9. Check Point FireWall-1 H.323 Protocol Implementation Vulnerabilities


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
BlackBerry Enterprise Server PDF Processing Vulnerability
2.
Sun Solaris System Management Agent SNMP Daemon Buffer Overflow
3.
Vim configure.in Insecure Temporary Files
4.
tplSoccerSite Multiple SQL Injection Vulnerabilities
5.
IBM WebSphere Application Server Unspecified Vulnerability
6.
MRO Maximo Information Disclosure and Cross-Site Scripting
7.
ArticleBeach Script "page" File Inclusion Vulnerability
8.
LunarNight Laboratory WebProxy Cross-Site Scripting
9.
Joomla DT Register Component "eventId" SQL Injection
10.
phpHoo3 "viewCat" SQL Injection Vulnerability





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia