SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#790771

HTTP Parsing Vulnerabilities in Check Point Firewall-1

Overview

Several versions of Check Point Firewall-1 contain a vulnerability that allows remote attackers to execute arbitrary code with administrative privileges.

I. Description

The HTTP Security Servers component of Check Point Firewall-1 contains an HTTP parsing vulnerability that is triggered by sending an invalid HTTP request through the firewall. When Firewall-1 generates an error message in response to the invalid request, a portion of the input supplied by the attacker is included in the format string for a call to sprintf().

Researchers at Internet Security Systems have determined that it is possible to exploit this format string vulnerability to execute commands on the firewall. The researchers have also determined that this vulnerability can be exploited as a heap overflow, which would allow an attacker to execute arbitrary code. In either case, the commands or code executed by the attacker would run with administrative privileges, typically "SYSTEM" or "root". For more information, please see the ISS advisory.

II. Impact

This vulnerability allows remote attackers to execute arbitrary code on affected firewalls with administrative privileges, typically "SYSTEM" or "root".

III. Solution

Apply the patch from Check Point


Check Point has published a "Firewall-1 HTTP Security Server Update" to address this vulnerability. For more information, please see the Check Point bulletin at:


Disable the affected components

Check Point has reported that their products are only affected by this vulnerability if the HTTP Security Servers feature is enabled. Therefore, affected sites may be able to limit their exposure to this vulnerability by disabling HTTP Security Servers.

Systems Affected

VendorStatusDate NotifiedDate Updated
Check PointVulnerable6-Feb-2004

References

http://www.us-cert.gov/cas/techalerts/TA04-036A.html
http://www.checkpoint.com/techsupport/alerts/security_server.html
http://xforce.iss.net/xforce/alerts/id/162
http://xforce.iss.net/xforce/xfdb/14149
http://www.secunia.com/advisories/10794/

Credit

This vulnerability was discovered and researched by Mark Dowd of ISS X-Force.

This document was written by Jeffrey P. Lanza.

Other Information

Date Public:2004-02-04
Date First Published:2004-02-05
Date Last Updated:2004-04-23
CERT Advisory: 
CVE-ID(s):CAN-2004-0039
NVD-ID(s):CAN-2004-0039
US-CERT Technical Alerts: 
Metric:17.10
Document Revision:30

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader