CERT-In Advisory
CIAD-2004-0017
Check Point VPN-1 ASN.1 Decoding Heap Overflow Vulnerability
Original Issue Date: July 29, 2004
Severity Rating: High
Systems Affected
- Check Point FireWall-1 GX 2.x Check Point Provider-1
- Check Point SSL Network Extender
- Check Point VPN-1 SecureClient
- Check Point VPN-1 SecuRemote
- Check Point VPN-1/Firewall-1 NG
- Check Point VPN-1/FireWall-1 NG with Application Intelligence AI
- Check Point VPN-1/FireWall-1 VSX NG
Overview
A vulnerability has been discovered in the ASN.1 decoding library within various Check Point VPN-1 products, which can be exploited to compromise a vulnerable system.
Description
Check Point VPN-1 is used to provide secure remote access to private networks from un-trusted network environments. A vulnerability has been discovered in the ASN.1 decoding library within the VPN-1 product which could make it possible for a malicious user to cause a buffer overflow when establishing an encrypted connection to a virtual private network VPN .
An unauthenticated remote attacker can trigger this vulnerability through a single-packet attack. Further, it may be possible for attackers to conceal the source of attacks and perform a blind-spoofed attack if UDP-based IKE negotiation is enabled.
Solution
Check Point has recommended that customers install an update on the enforcement modules of the affected products. The issue has been addressed in the most recent Hotfix Accumulators HFAs and ASN.1 Hotfixes. Software Subscription customers can download updates for affected products from the Check Point site.
Vendor Information
Check Point:
References
Secunia
http://secunia.com/advisories/12177/
ISS
http://xforce.iss.net/xforce/alerts/id/178
Zone-h
http://www.zone-h.org/en/advisories/read/id=5158/
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|