Advertisement
Promo

Mobile working Toolkit in association with http://marketing.ianywhere.com/forms/EMEA09SUPSybaseMobilityLeadership-IDC

Check Point hit by VPN vulnerability

Graeme Wearden ZDNet.co.uk

Published: 10 May 2004 13:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies who use one of Check Point's virtual private networking applications have been urged to patch their systems after the discovery of a security hole in the products.

The vulnerability could allow a hacker to break into a supposedly secure connection set up through one of Check Point's VPN-1 applications, the company warned last week. In some circumstances, a company's wider network could also be under threat.

Customers who have already upgraded to one of the latest versions of Check Point's VPN-1 range should be safe, but those who haven't should visit the company's Web site to download a fix. Windows, Linux, Solaris, SecurePlatform and IPSO versions are all affected.

"Check Point knows of no organisations that have had systems affected by this issue. However, in order to protect VPN-1 Gateways, Check Point recommends that customers install an update on all enforcement modules," said the company.

The flaw in question concerns ISAKMP (Internet Security Association & Key Management Protocol), the networking protocol that allows the VPN server and client to confirm each other's identity by exchanging a key before the secure connection will be set up.

If a specially engineered packet is received by an unpatched server during the ISAKMP negotiations, then this will cause a buffer overrun that compromises the security of the VPN link.

Click here to download a patch from Check Point's site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
88 out of 169 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

Video icon

Video

On The Road Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

The Right Mouse for the Job

It seems to me that the computer mouse is often almost an afterthought, or even gets no thought at all, when configuring or setting up a computer. In many cases (I might even go so... More

Post a comment

Apple patents point to haptics, finger...

Three patent applications made by Apple were published on Thursday, covering technologies including haptics, fingerprint recognition and RFID. The haptic feedback patent, if approved,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters