|
Check Point FireWall-1 multiple vulnerabilities
|
|
Secunia Advisory:
|
SA8371
|
|
|
Release Date:
|
2003-03-21
|
|
Last Update:
|
2003-03-28
|
|
Popularity:
|
6,294 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Partial Fix
|
|
| Software: | Check Point Firewall-1 4.x Check Point VPN-1/Firewall-1 NG
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: Two vulnerabilities have been discovered in the syslog daemon included in some versions of Check Point FireWall-1.
One vulnerability allows people to crash the syslog daemon by sending large amounts of data to the syslog service. It has been discussed whether this vulnerability could be exploited to execute arbitrary code, but it has not been proven.
The other allows malicious users to inject malicious characters such as console escape sequences. This could be dangerous depending on the utility used to read the log files.
The syslog service is not enabled by default.
The vulnerability has been confirmed in the following versions:
* Check Point FW-1 NG FP3
* Check Point FW-1 NG FP2
* Check Point FW-1 4.1 SP6
Solution: Secunia recommends that you use a dedicated host for remote logging. It is an unnecessary risk to run it on your firewall - no matter how convenient it may be.
An update (HF2) fixing the first issue is available via SmartUpdate or from:
http://www.checkpoint.com/techsupport/ng/fp3_hotfix.html
The other issue concerning injection of malicious characters has not been fixed. We recommend that you use a different syslog server or filter the log files with some other tool before viewing them.
Provided and/or discovered by: Dr. Peter Bieringer
Changelog: 2003-03-28: Added vulnerable versions in "Description" and link in "Original Advisory".
Original Advisory: http://www.aerasec.de/security/adviso...heckpoint-fw1-ng-fp3-syslog-crash.txt
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|