First published: Fri Mar 15 2002(Updated: )
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Check Point FireWall-1 | =3.0b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1171 is considered a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2001-1171, update the Check Point Firewall-1 software to a version that does not create world-writable temporary files.
CVE-2001-1171 affects users of Check Point Firewall-1 versions 3.0b through 4.0 SP1.
Attackers can exploit CVE-2001-1171 to modify firewall policy or gain unauthorized access to system privileges.
CVE-2001-1171 was disclosed in September 2001.