| CERT-In Advisory  
                                                                      CIAD-2004-0017Check Point VPN-1 ASN.1 Decoding Heap Overflow VulnerabilityOriginal Issue Date: July      29, 2004
 Severity Rating: High
 Systems Affected  
Check Point FireWall-1 GX 2.x Check Point Provider-1 
Check Point SSL Network Extender 
Check Point VPN-1 SecureClient 
Check Point VPN-1 SecuRemote 
Check Point VPN-1/Firewall-1 NG 
Check Point VPN-1/FireWall-1 NG with Application Intelligence  AI  
Check Point VPN-1/FireWall-1 VSX NG  Overview  A vulnerability has been discovered in the ASN.1 decoding library within various Check Point VPN-1 products, which can be exploited to compromise a vulnerable system.  Description Check Point VPN-1 is used to provide secure remote access to private networks from un-trusted network environments.  A vulnerability has been discovered in the ASN.1 decoding library within the VPN-1 product which could make it possible for a malicious user to cause a buffer overflow when establishing an encrypted connection to a virtual private network  VPN .  
 An unauthenticated remote attacker can trigger this vulnerability through a single-packet attack. Further, it may be possible for attackers to conceal the source of attacks and perform a blind-spoofed attack if UDP-based IKE negotiation is enabled.
 
 
 Solution  Check Point has recommended that customers install an update on the enforcement modules of the affected products.  The issue has been addressed in the most recent Hotfix Accumulators  HFAs  and ASN.1 Hotfixes. Software Subscription customers can download updates for affected products from the Check Point site. 
 Vendor InformationCheck Point: 
 References Secunia http://secunia.com/advisories/12177/
 
 ISS http://xforce.iss.net/xforce/alerts/id/178
 
 Zone-hDisclaimerhttp://www.zone-h.org/en/advisories/read/id=5158/
 
 The information provided herein is on "as is" basis, without warranty of any kind.Contact Information Email: info@cert-in.org.in  Phone: +91-11-2436857Postal address Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology
 Government of India
 Electronics Niketan
 6, CGO Complex, Lodhi Road,
 New Delhi - 110 003
 India
   |