ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile working Toolkit

Check Point hit by VPN vulnerability

Graeme Wearden ZDNet.co.uk

Published: 10 May 2004 13:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies who use one of Check Point's virtual private networking applications have been urged to patch their systems after the discovery of a security hole in the products.

The vulnerability could allow a hacker to break into a supposedly secure connection set up through one of Check Point's VPN-1 applications, the company warned last week. In some circumstances, a company's wider network could also be under threat.

Customers who have already upgraded to one of the latest versions of Check Point's VPN-1 range should be safe, but those who haven't should visit the company's Web site to download a fix. Windows, Linux, Solaris, SecurePlatform and IPSO versions are all affected.

"Check Point knows of no organisations that have had systems affected by this issue. However, in order to protect VPN-1 Gateways, Check Point recommends that customers install an update on all enforcement modules," said the company.

The flaw in question concerns ISAKMP (Internet Security Association & Key Management Protocol), the networking protocol that allows the VPN server and client to confirm each other's identity by exchanging a key before the secure connection will be set up.

If a specially engineered packet is received by an unpatched server during the ISAKMP negotiations, then this will cause a buffer overrun that compromises the security of the VPN link.

Click here to download a patch from Check Point's site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
83 out of 164 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Team Manager - Intensive

Visit www.rackspace.co.uk/recruitmentvideo. Delivery of optimal customer service Fanatical SupportTM - Minimisation of downtime via proactive ...

Embedded C / C++ protocol stack engineer - Berks - Up to 50k!

My client is now looking for embedded C / C++ protocol stack engineer. You will be reliable for working on all layers of the protocol stack where you ...

SAP BW consultant required - Excellent BI training opportunities!!

My team and I recruit SAP permanent skills across the Midlands and across the SAP modules so if this is not of interest but you are looking then ...

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

Post a comment