Check Point Firewall-1/VPN-1 Management Station Format String Vulnerability
BID:3021
Info
Check Point Firewall-1/VPN-1 Management Station Format String Vulnerability
| Bugtraq ID: | 3021 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2001 12:00AM |
| Updated: | Jul 11 2001 12:00AM |
| Credit: | Discovery credited to Halvar Flake of BlackHat Consulting. |
| Vulnerable: |
Nokia IPSO 3.3 SP3 Nokia IPSO 3.3 SP2 Nokia IPSO 3.3 SP1 Nokia IPSO 3.3 Check Point Software VPN-1 4.1 SP3 Check Point Software VPN-1 4.1 SP1 Check Point Software VPN-1 4.1 Check Point Software Provider-1 4.1 SP3 Check Point Software Provider-1 4.1 SP2 Check Point Software Provider-1 4.1 SP1 Check Point Software Provider-1 4.1 Check Point Software Firewall-1 4.1 SP3 Check Point Software Firewall-1 4.1 SP2 Check Point Software Firewall-1 4.1 SP1 Check Point Software Firewall-1 4.1 |
| Not Vulnerable: |
Nokia IPSO 3.3 SP4 Check Point Software VPN-1 4.1 SP4 Check Point Software Provider-1 4.1 SP4 Check Point Software Firewall-1 4.1 SP4 |
Discussion
Check Point Firewall-1/VPN-1 Management Station Format String Vulnerability
Firewall-1/VPN-1 management station contains a format string vulnerability.
The vulnerability is the result of passing client-supplied data to a printf* function as the format string argument.
This vulnerability can only be exploited by a client that is authenticated as an administrator and connected from an authorized IP address.
Administrators with limited privileges (such as read-only) may be able to exploit this vulnerability to gain control over the management station.
Firewall-1/VPN-1 management station contains a format string vulnerability.
The vulnerability is the result of passing client-supplied data to a printf* function as the format string argument.
This vulnerability can only be exploited by a client that is authenticated as an administrator and connected from an authorized IP address.
Administrators with limited privileges (such as read-only) may be able to exploit this vulnerability to gain control over the management station.
Exploit / POC
Check Point Firewall-1/VPN-1 Management Station Format String Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.