6.4
CVSSv2

CVE-2001-1101

Published: 08/09/2001 Updated: 19/12/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b up to and including 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

checkpoint firewall-1 4.0

checkpoint firewall-1 4.1

checkpoint firewall-1 3.0