About
Subscribe

CheckPoint hits out at critic

Carel Alberts
By Carel Alberts, ITWeb contributor
Johannesburg, 11 Feb 2004

CheckPoint has reacted angrily to a report by System (ISS), an Internet security firm, which claimed that some versions of its products are open to attack.

Although it does not contest existence of the vulnerabilities, a prepared statement called the version references inaccurate, and the report "negligent" and "a blatant attempt to market...products".

Following the report of critical vulnerabilities and exploits, CheckPoint urged its firewall and virtual private customers to patch their systems or upgrade software.

It had reacted to an ISS report that the flaws "could allow attackers to enter networks and crash computers". According to ISS, the FireWall-1 HTTP parsing format string vulnerabilities affected HTTP security servers on NG versions, while the VPN-1, SecuRemote and SecureClient ISAKMP Buffer Overflow affected VPN servers and clients on pre-NG FP2 versions, including v 4.1.

'Not susceptible`

Niall Moynihan, northern European technical director for CheckPoint, says contrary to ISS`s initial security alert, the most recent versions of CheckPoint VPN-1 Versions 4.1 and NG are not susceptible to this vulnerability.

"This issue was resolved with Next Generation FP2, released in April 2002 and 4.1 SP6, released in June 2002," says Moynihan. "It appears that ISS did not adequately test version 4.1 SP6 prior to listing it as affected. After being notified of the error, ISS requested access to SP6 for testing. CheckPoint provided the software and ISS has since confirmed that no vulnerability exists in VPN-1 4.1 SP6 and updated their security advisory accordingly."

More information can be found here.

As regards ISS`s FireWall-1 statement, Moynihan says the company had initially characterised this vulnerability as affecting all aspects of HTTP inspection in Application Intelligence. "The issue described is related only to the HTTP Security Server," he explains. "CheckPoint has issued a simple update to a configuration file to mitigate this issue."

More information can be found here.

"CheckPoint sincerely apologises for any confusion this inaccurate information from ISS may have caused our customers," Moynihan concludes.

ISS`s UK and Ireland regional spokesman was not immediately available for comment. SA customer sites for CheckPoint number in the hundreds.

Related story:
CheckPoint fixes flaws

Share