Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

[Print][Mobile][Alerts]

Check Point in Firewall-1 security flap

Fire in the hole!

Published Wednesday 11th February 2004 10:10 GMT

Check Point has plugged a serious security vulnerability affecting several versions of its flagship security platform, Firewall-1.

The problem stems from a flaw in the Application Intelligence (AI) component of Firewall-1, which is meant to detect application level attacks, but is itself vulnerable to format string or heap buffer overflow attacks.

Earlier versions of Firewall-1 include the HTTP Security Server, which provides similar functionality, are similarly vulnerable.

Flaws in Firewall-1 are uncommon are this one is far worse than most because it strikes at commonly deployed subsets of Check Point's technology not problems with in obscure configurations or settings.

Various versions of Check Point Firewall-1 NG and Check Point Firewall-1 NG with Application Intelligence are affected by the problem, which could be exploited to launch DoS attacks on the affected firewalls. Worse still the vulnerability could be used by a skilled attacker to run arbitrary code and thereby to take control of the firewall and the server it runs on.

An advisory by US-CERT explains the issue in greater depth. The problem was discovered by researchers at security tools vendor ISS

Check Point has released an advisory here. ®

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
  • Microsoft System Center - Designed For Big
  • Meet the fast-growing demand for notebooks with HP
  • Find out how to eradicate 99.7% of spam, click here
  • From small embedded OS to the world's most used open mobile OS
whitepaper title

Server Consolidation and Containment

This paper discusses how consolidation and containment solutions with a virtual infrastructure meet the challenges of server sprawl and underutilization..
whitepaper title

Making Green IT a Reality

Customer Perspectives on the Impact of Storage Vendor Decisions on Power, Cooling, & Space in Enterprise Data Centers.
Whitepapers Jobs

Top 20 storiesAll The Week’s HeadlinesArchiveSearch