ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile working Toolkit

Check Point plugs VPN security hole

Munir Kotadia ZDNet.co.uk

Published: 29 Jul 2004 13:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security appliance vendor Check Point issued a patch on Wednesday to fix vulnerabilities that could allow hackers to take control of certain VPN and firewall appliances and gain network access.

Check Point said it discovered an ASN.1 issue in its VPN-1 products that left them vulnerable to a buffer overrun error that could be exploited while the system is setting up a secure VPN tunnel.

To exploit a buffer-overrun vulnerability, an attacker can send specially crafted packets of information to the appliance that are designed to cause confusion and create an opportunity for the attacker to take control of the product.

Check Point admits the problem "could allow further network compromise", but claims that it does not know of any companies that have been affected by the issue.

According to Check Point, customers are only at risk if Aggressive Mode IKE is implemented and they use remote access VPNs, gateway-to-gateway VPNs and have not upgraded to the latest product versions. The VPN-1/FireWall-1 R55 HFA-08, R54 HFA-412, and VPN-1 SecuRemote/SecureClient R56 HF1 are not at risk.

Check Point recommends that customers with a valid subscription download and deploy the relevant hotfix as soon as possible. Customers that have allowed their service contracts to expire can still obtain the update by contacting Check Point's technical support team.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
69 out of 174 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Network Firewall Support Engineer - 35,000 - York

Network Firewall Support Engineer ( CCSA, CCSA, Cisco, Checkpoint, VPN, PIX, ASA, Nokia IPSO, Solaris ) required. All candidates must have in-depth ...

Network Operations Manager

Appointments subject to Criminal Records Bureau check. This will include server and network infrastructure management, management of all areas of ...

Network Security Administrator Level 2 (CCNA, CCNP)

Your role will comprise of; - Performing required maintenance for installation, configuration, and updates to firewalls, and VPN connections - ...

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment