Skip navigation

Denial of Service in Checkpoint NG FW-1/VPN-1 Client Component

Reported March 24, 2003, by Checkpoint.

 

 

VERSIONS AFFECTED

 

  • Checkpoint VPN-1/FW-1 Client versions prior to Next Generation (NG) Feature Pack 3 (FP3) Hotfix-2

 

DESCRIPTION

 

A new vulnerability in Checkpoint VPN-1/FW-1 Client versions prior to Next Generation (NG) Feature Pack 3 (FP3) Hotfix-2 can result in a Denial of Service (DoS) condition. By sending excessive amounts of data through a syslog connection, an attacker can cause the SmartTracker logging mechanism on the target firewall to experience high CPU utilization rates and crash without notice. You must manually restart the service to return to normal operations.

 

VENDOR RESPONSE

 

Checkpoint has released Hotfix-2 to address this vulnerability and recommends that affected users immediately apply the patch mentioned in the bulletin.

 

CREDIT          

Discovered by Dr. Peter Bieringer of AERAsec Network Services and Security GmbH.

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish