First published: Wed Apr 17 2019(Updated: )
A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.
Credit: cve@checkpoint.com cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Checkpoint Zonealarm | <=15.4.062 | |
<=15.4.062 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8455 is a vulnerability found in Check Point ZoneAlarm up to version 15.4.062, which allows a local attacker to gain higher privileges by creating a hard link from a log file to another file on the system.
CVE-2019-8455 allows a local attacker to change the permissions of a linked file created from a log file, gaining higher privileges on files with limited access.
CVE-2019-8455 has a severity rating of 7.1 (high).
To fix CVE-2019-8455, update your Check Point ZoneAlarm software to version 15.4.062 or later.
You can find more information about CVE-2019-8455 on the following references: [http://www.securityfocus.com/bid/108029](http://www.securityfocus.com/bid/108029) and [https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960](https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960)