Advertisement
Promo

Mobile working Toolkit in association with http://marketing.ianywhere.com/forms/EMEA09SUPSybaseMobilityLeadership-IDC

Check Point plugs VPN security hole

Munir Kotadia ZDNet.co.uk

Published: 29 Jul 2004 13:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security appliance vendor Check Point issued a patch on Wednesday to fix vulnerabilities that could allow hackers to take control of certain VPN and firewall appliances and gain network access.

Check Point said it discovered an ASN.1 issue in its VPN-1 products that left them vulnerable to a buffer overrun error that could be exploited while the system is setting up a secure VPN tunnel.

To exploit a buffer-overrun vulnerability, an attacker can send specially crafted packets of information to the appliance that are designed to cause confusion and create an opportunity for the attacker to take control of the product.

Check Point admits the problem "could allow further network compromise", but claims that it does not know of any companies that have been affected by the issue.

According to Check Point, customers are only at risk if Aggressive Mode IKE is implemented and they use remote access VPNs, gateway-to-gateway VPNs and have not upgraded to the latest product versions. The VPN-1/FireWall-1 R55 HFA-08, R54 HFA-412, and VPN-1 SecuRemote/SecureClient R56 HF1 are not at risk.

Check Point recommends that customers with a valid subscription download and deploy the relevant hotfix as soon as possible. Customers that have allowed their service contracts to expire can still obtain the update by contacting Check Point's technical support team.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
69 out of 177 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

On The Road Blog

Looking forward to 2010. Part 1 – Kill...

Analyst and futurist Mark Anderson’s annual predictions often leave you with plenty to think about. He’s one of those people with their finger on the pulse of the world – and not just... More

1 comment

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Using Bluetooth on Linux

I have mentioned before that I use a number of Bluetooth peripherals with my portable computers. This is one of those things where, the more I use it the more I like it. I've now... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters