List Info

Thread: New SmartDefense Updates




New SmartDefense Updates
user name
2006-03-01 23:10:53
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

  
Greetings!

Several new SmartDefense Updates were published today, March
1 , 2006 for
users of VPN-1 NGX R60, VPN-1 NG with Application
Intelligence R54, R55 &
R55W, and users of InterSpect NGX & 2.0. The following
protections were
added:

Microsoft Windows Web Client Service Protection (MS06-008):
Several
versions of the Microsoft Windows operating system are
shipped with a
WebDAV service, referred to by Microsoft as the Web Client
service. The Web
Client service allows applications to access documents on
the Internet by
using the WebDAV protocol.  A vulnerability was detected in
the Web Client
service. A remote authenticated attacker could exploit this
vulnerability
by crafting a RPC call to the affected service. To exploit
the
vulnerability, an attacker would first have to authenticate
to the system.
Successful exploitation will grant the attacker complete
control of the
affected system.  The update blocks the WebDAV MS-RPC
interface over Common
Internet File Sharing (CIFS) protocol. For more information,
refer to
CPAI-2006-018 at
http://www.checkpoint.com/defense/advi
sories/public/2006/cpai-19-Feb.html. 

Microsoft Windows EMF/WMF Protection (MS06-004): Internet
Explorer 5.01
Service Pack 4 fails to properly handle Windows Metafile
(WMF) and Enhanced
Metafile (EMF) image formats.  WMF and EMF are image formats
used in many
Windows programs including Internet Explorer and Outlook. By
persuading a
user to
Visit a malicious Web site or open a specially crafted email
attachment, an
attacker may be able to execute arbitrary code on the
affected system. The
protection
detects WMF and EMF files over the configured HTTP ports and
blocks the
connection when it detects these files. For more
information, refer to
CPAI-2006-020 at
http://www.checkpoint.com/defense/advis
ories/public/2006/cpai-18-Feb.html

Links to the recent SmartDefense Advisories are available
at:
http://www.checkpoint.com/defense/advisories/pub
lic/summary.html 
 
Read more about SmartDefense Service at:
http://www.checkpoint.com/defense/advisories/pu
blic/overview.html 

To sign-up to the mailing list, send an email to
listservamadeus.us.checkpoint.com with the text
"SUBSCRIBE
SMARTDEFENSE-NEWS" in the email body.

To unsubscribe from this list, send an email to
listservamadeus.us.checkpoint.com with the text
"SIGNOFF
SMARTDEFENSE-NEWS" in the email body.

As always, please feel free to contact us directly if you
have any comments
or questions (sda-infoCheckPoint.com). 


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQA/AwUBRAYp3lqiP0SjohCrEQLyhgCeIWcqNSJqg+uuKnOPrOy/zM1WM60A
n3s0
slhvP1IqqrwyfLeRVy6cn29F
=xqh1
-----END PGP SIGNATURE-----
[1]

about | contact  Other archives ( Real Estate discussion Medical topics )