Advertisement
Promo

Mobile working Toolkit in association with http://marketing.ianywhere.com/forms/EMEA09SUPSybaseMobilityLeadership-IDC

Check Point hit by VPN vulnerability

Graeme Wearden ZDNet.co.uk

Published: 10 May 2004 13:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies who use one of Check Point's virtual private networking applications have been urged to patch their systems after the discovery of a security hole in the products.

The vulnerability could allow a hacker to break into a supposedly secure connection set up through one of Check Point's VPN-1 applications, the company warned last week. In some circumstances, a company's wider network could also be under threat.

Customers who have already upgraded to one of the latest versions of Check Point's VPN-1 range should be safe, but those who haven't should visit the company's Web site to download a fix. Windows, Linux, Solaris, SecurePlatform and IPSO versions are all affected.

"Check Point knows of no organisations that have had systems affected by this issue. However, in order to protect VPN-1 Gateways, Check Point recommends that customers install an update on all enforcement modules," said the company.

The flaw in question concerns ISAKMP (Internet Security Association & Key Management Protocol), the networking protocol that allows the VPN server and client to confirm each other's identity by exchanging a key before the secure connection will be set up.

If a specially engineered packet is received by an unpatched server during the ISAKMP negotiations, then this will cause a buffer overrun that compromises the security of the VPN link.

Click here to download a patch from Check Point's site.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
89 out of 190 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

Video icon

Video

On The Road Blog

Nokia halves smartphone portfolio

Nokia has reduced the number of smartphone models it intends to introduce in 2010 by half, according to reports. Quoted in an article on Reuters, the Finnish handset maker's new... More

1 comment

Can I have fries with that? (Consumer...

Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

1 comment

Lenovo repurchases mobile phone arm

Lenovo has bought back the mobile phone arm that it sold to a private equity firm at the start of 2008, the company said on Friday. The manufacturer sold Lenovo Mobile to the Hony... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters