exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Secunia Security Advisory 13792

Secunia Security Advisory 13792
Posted Jan 16, 2005
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A weakness has been reported in Check Point Firewall-1 NG with SmartDefense, which allows malware to bypass detection.

tags | advisory
SHA-256 | 591ae33f7ad522ffc27ec1a6c373a6fcfbf8b3817c30dc85514fe40a15d422ba

Secunia Security Advisory 13792

Change Mirror Download

TITLE:
Check Point Firewall-1 NG SmartDefense RFC2397 Bypass Weakness

SECUNIA ADVISORY ID:
SA13792

VERIFY ADVISORY:
http://secunia.com/advisories/13792/

CRITICAL:
Not critical

IMPACT:
Security Bypass

WHERE:
>From remote

SOFTWARE:
Check Point VPN-1/FireWall-1 NG with Application Intelligence (AI)
http://secunia.com/product/2542/

DESCRIPTION:
A weakness has been reported in Check Point Firewall-1 NG with
SmartDefense, which allows malware to bypass detection.

The weakness is caused due to a lack of RFC2397 support. This can be
exploited to bypass the malware detection by sending malicious image
files, which are base64 encoded and embedded in an HTML file
according to the standard specified in RFC2397, which is supported by
a number of client applications capable of rendering HTML files (e.g.
email clients and browsers).

A PoC has been published, which embeds an image that attempts to
exploit the GDI+ JPEG parsing vulnerability in Microsoft Windows.

NOTE: Content inspection software can generally be bypassed in many
ways by obfuscating data and exploit code. However, this advisory
describes lack of compliance with a widely deployed standard for
embedding pictures in HTML files.

This has been reported to affect Check Point Firewall-1 NG R55 HFA08
with SmartDefense 541041226. Other versions may also be vulnerable.

SOLUTION:
Do not rely solely on gateway / perimeter security.

Apply patches to fix vulnerabilities in client software and apply
other defence in depth measures.

PROVIDED AND/OR DISCOVERED BY:
Darren Bounds, Intrusense.

ORIGINAL ADVISORY:
http://www.intrusense.com/av-bypass/image-bypass-advisory.txt

OTHER REFERENCES:
SA12528:
http://secunia.com/advisories/12528/

RFC2397:
http://www.ietf.org/rfc/rfc2397.txt

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close