PT-2004-1254 · Check Point · Check Point Firewall-1 Http Security Server+1
Mark Dowd
·
Publicado
2004-02-11
·
Atualizado
2017-07-11
·
CVE-2004-0039
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Check Point Firewall-1 NG-AI versions R54 through R55
Check Point Firewall-1 HTTP Security Server included with NG FP1 through FP3
Description
The issue allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message. This can be demonstrated using the scheme of a URI.
Recommendations
For Check Point Firewall-1 NG-AI versions R54 through R55, update to a version that includes the fix for this issue.
For Check Point Firewall-1 HTTP Security Server included with NG FP1 through FP3, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the HTTP Application Intelligence component until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Check Point Firewall-1 Http Security Server
Check Point Firewall-1 Gui