Check Point Patches Severe FireWall-1 Flaws | eWeek

Check Point Patches Severe FireWall-1 Flaws

Written By
Dennis Fisher
Dennis Fisher
Feb 5, 2004
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Check Point Software Technologies Ltd. on Wednesday released a fix for a set of severe security vulnerabilities in its FireWall-1 product that enable attackers to execute commands on the vulnerable server.

The problems are a group of format string flaws that appears when FireWall-1 attempts to validate HTTP requests, according to analysts at Internet Security Systems Inc., which discovered the flaws. Error messages created when an invalid portion of a request is specified allow attackers to provide their own format string specifiers. This in turn can lead to corruption of memory and give attackers the ability to run their own code on the server with super-user privileges.

FireWall-1 is among the more widely deployed enterprise firewalls on the Internet.

Although ISS officials said exploiting the vulnerabilities is difficult on some platforms, the company has developed an exploit that works reliably. And, even failed attacks can interrupt all of the current HTTP sessions on the FireWall-1 server.

The vulnerability affects FireWall-1 NG with Application Intelligence, FireWall-1 4.1 and FireWall-1 HTTP Security Server, which is included with NG FP1, 2 and 3.

ISS also found a vulnerability in an old version of Check Points VPN-1 product, which the company no longer supports. Check Point, based in Ramat Gan, Israel, does not plan to release a patch for this issue.

Check out eWEEK.coms Security Center at security.eweek.com for security news, views and analysis.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.