Vulnerability Note VU#790771
HTTP Parsing Vulnerabilities in Check Point Firewall-1
Overview
Several versions of Check Point Firewall-1 contain a vulnerability that allows remote attackers to execute arbitrary code with administrative privileges.
Description
The HTTP Security Servers component of Check Point Firewall-1 contains an HTTP parsing vulnerability that is triggered by sending an invalid HTTP request through the firewall. When Firewall-1 generates an error message in response to the invalid request, a portion of the input supplied by the attacker is included in the format string for a call to sprintf(). Researchers at Internet Security Systems have determined that it is possible to exploit this format string vulnerability to execute commands on the firewall. The researchers have also determined that this vulnerability can be exploited as a heap overflow, which would allow an attacker to execute arbitrary code. In either case, the commands or code executed by the attacker would run with administrative privileges, typically "SYSTEM" or "root". For more information, please see the ISS advisory. |
Impact
This vulnerability allows remote attackers to execute arbitrary code on affected firewalls with administrative privileges, typically "SYSTEM" or "root". |
Solution
Apply the patch from Check Point |
Disable the affected components
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Check Point | Affected | 02 Feb 2004 | 06 Feb 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.us-cert.gov/cas/techalerts/TA04-036A.html
- http://www.checkpoint.com/techsupport/alerts/security_server.html
- http://xforce.iss.net/xforce/alerts/id/162
- http://xforce.iss.net/xforce/xfdb/14149
- http://www.secunia.com/advisories/10794/
Credit
This vulnerability was discovered and researched by Mark Dowd of ISS X-Force.
This document was written by Jeffrey P. Lanza.
Other Information
- CVE IDs: CAN-2004-0039
- Date Public: 04 Feb 2004
- Date First Published: 05 Feb 2004
- Date Last Updated: 23 Apr 2004
- Severity Metric: 17.10
- Document Revision: 30
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.