CVE-2001-1101
Last modified
CVE-2001-1101 is a vulnerability of currently unknown severity. The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Checkpoint | Firewall-1 | 3.0 |
| Checkpoint | Firewall-1 | 4.0 |
| Checkpoint | Firewall-1 | 4.1 |
References
- http://www.securityfocus.com/archive/1/212826Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3303Vendor Advisory
- http://www.securityfocus.com/archive/1/212826Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3303Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1101?
How severe is CVE-2001-1101?
How do I fix CVE-2001-1101?
Are you affected by CVE-2001-1101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
