Check Point Firewall-1 GUI Client Log Viewer Symbolic Link Vulnerability
BID:3303
Info
Check Point Firewall-1 GUI Client Log Viewer Symbolic Link Vulnerability
| Bugtraq ID: | 3303 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2001-1101 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 08 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced by Alan Darien <[email protected]> via Bugtraq on September 8, 2001. |
| Vulnerable: |
Check Point Software Firewall-1 4.1 SP2 Check Point Software Firewall-1 4.1 SP1 Check Point Software Firewall-1 4.1 Check Point Software Firewall-1 4.0 Check Point Software Firewall-1 3.0 |
| Not Vulnerable: |
Check Point Software Firewall-1 4.1 SP4 |
Discussion
Check Point Firewall-1 GUI Client Log Viewer Symbolic Link Vulnerability
Check Point Firewall-1 is a commercial firewall implementation designed for small to enterprise sized networks.
A problem with Firewall-1 makes it possible for a local user to overwrite critical system files. Firewall-1 does not check for the existance of files when saving files through the Log Viewer function. Log Viewer will overwrite files ending in the .log extension, and will following symbolic links to corrupt root-owned files.
This makes it possible for a user with administrative access to Firewall-1 and local shell access to deny service to legitimate users of the system.
Check Point Firewall-1 is a commercial firewall implementation designed for small to enterprise sized networks.
A problem with Firewall-1 makes it possible for a local user to overwrite critical system files. Firewall-1 does not check for the existance of files when saving files through the Log Viewer function. Log Viewer will overwrite files ending in the .log extension, and will following symbolic links to corrupt root-owned files.
This makes it possible for a user with administrative access to Firewall-1 and local shell access to deny service to legitimate users of the system.
Exploit / POC
Check Point Firewall-1 GUI Client Log Viewer Symbolic Link Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Check Point Firewall-1 GUI Client Log Viewer Symbolic Link Vulnerability
Solution:
Upgrade to Check Point FireWall-1 version 4.1 Service Pack 2 or later.
Solution:
Upgrade to Check Point FireWall-1 version 4.1 Service Pack 2 or later.
References
Check Point Firewall-1 GUI Client Log Viewer Symbolic Link Vulnerability
References:
References: