Check Point Firewall-1 Policyname Temporary File Creation Vulnerability
BID:3300
Info
Check Point Firewall-1 Policyname Temporary File Creation Vulnerability
| Bugtraq ID: | 3300 |
| Class: | Race Condition Error |
| CVE: |
CVE-2001-1102 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 08 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced by Alan Darien <[email protected]> via Bugtraq on September 8, 2001. |
| Vulnerable: |
Check Point Software Firewall-1 4.1 SP1 Check Point Software Firewall-1 4.1 Check Point Software Firewall-1 4.0 Check Point Software Firewall-1 3.0 |
| Not Vulnerable: |
Check Point Software Firewall-1 4.1 SP4 Check Point Software Firewall-1 4.1 SP3 Check Point Software Firewall-1 4.1 SP2 |
Discussion
Check Point Firewall-1 Policyname Temporary File Creation Vulnerability
Check Point Firewall-1 is a commercial firewall implementation designed for small to enterprise sized networks.
A problem with Firewall-1 has been discovered that makes it possible for a local user to change the permissions of root-owned files to world-writable, and potentially gain elevated privileges. The problem is in the creation of predictable /tmp files. Upon editing firewall rules and committing them, a file is created in /tmp using the name of the policy as a filename, and .cpp as an extension.
It's possible for a local user to create symbolic links to root-owned files, which will result in the files becoming world-writable, and potentially gain local root access.
Check Point Firewall-1 is a commercial firewall implementation designed for small to enterprise sized networks.
A problem with Firewall-1 has been discovered that makes it possible for a local user to change the permissions of root-owned files to world-writable, and potentially gain elevated privileges. The problem is in the creation of predictable /tmp files. Upon editing firewall rules and committing them, a file is created in /tmp using the name of the policy as a filename, and .cpp as an extension.
It's possible for a local user to create symbolic links to root-owned files, which will result in the files becoming world-writable, and potentially gain local root access.
Exploit / POC
Check Point Firewall-1 Policyname Temporary File Creation Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
References
Check Point Firewall-1 Policyname Temporary File Creation Vulnerability
References:
References: