Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firewall-1 | Checkpoint | 3.0 (including) | 3.0 (including) |
Firewall-1 | Checkpoint | 4.0 (including) | 4.0 (including) |
Firewall-1 | Checkpoint | 4.1 (including) | 4.1 (including) |
Firewall-1 | Checkpoint | 4.1-sp1 (including) | 4.1-sp1 (including) |