Description
Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default "ANY" address and result in access to more systems than intended by the administrator.
Product(s):
- Check Point Firewall-1
- Checkpoint Firewall-1
- Checkpoint Firewall-1 3.0
- Checkpoint Firewall-1 3.0b
- Checkpoint Firewall-1 4.0
- Checkpoint Firewall-1 4.1
- Checkpoint Firewall-1 1 4.1 SP1
- Checkpoint Firewall-1 1 4.1 SP2
- Checkpoint Firewall-1 1 4.1 SP3
- Checkpoint Firewall-1 1 4.1 SP4
- Checkpoint Firewall-1 1 4.1 SP5
- Checkpoint Firewall-1 4.1 SP5a
- Checkpoint Firewall-1 4.1 SP6
- Checkpoint Firewall-1 4.1 Build 41439
- Checkpoint Firewall-1 R55W
- Checkpoint Firewall-1 R55W HFA1
- Checkpoint Firewall-1 R55W HFA2
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-1999-1204, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-1999-1204 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.