ID

VAR-200006-0091


CVE

CVE-2000-0582


TITLE

Check Point Firewall-1 SMTP Resource consumption vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200006-117

DESCRIPTION

Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy. The Check Point Firewall-1 SMTP Security Server in Firewall-1 4.0 and 4.1 on Windows NT is vulnerable to a simple network-based attack which can increase the firewall's CPU utilization to 100%. According to Check Point Software this only disables mail relay while allowing other firewall operations to continue normally. Vulnerabilities exist in Check Point FireWall-1 versions 4.0 and 4.1

Trust: 1.26

sources: NVD: CVE-2000-0582 // BID: 1416 // VULHUB: VHN-2159

AFFECTED PRODUCTS

vendor:checkpointmodel:firewall-1scope:eqversion:4.0

Trust: 1.6

vendor:checkpointmodel:firewall-1scope:eqversion:4.1

Trust: 1.6

vendor:checkmodel:point software firewall-1scope:eqversion:4.1

Trust: 0.3

vendor:checkmodel:point software firewall-1scope:eqversion:4.0

Trust: 0.3

sources: BID: 1416 // CNNVD: CNNVD-200006-117 // NVD: CVE-2000-0582

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2000-0582
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200006-117
value: MEDIUM

Trust: 0.6

VULHUB: VHN-2159
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2000-0582
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-2159
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-2159 // CNNVD: CNNVD-200006-117 // NVD: CVE-2000-0582

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2000-0582

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200006-117

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200006-117

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-2159

EXTERNAL IDS

db:BIDid:1416

Trust: 2.0

db:OSVDBid:1438

Trust: 1.7

db:NVDid:CVE-2000-0582

Trust: 1.7

db:CNNVDid:CNNVD-200006-117

Trust: 0.7

db:BUGTRAQid:20000630 SECUREXPERT ADVISORY [SX-20000620-3]

Trust: 0.6

db:EXPLOIT-DBid:20049

Trust: 0.1

db:SEEBUGid:SSVID-73947

Trust: 0.1

db:VULHUBid:VHN-2159

Trust: 0.1

sources: VULHUB: VHN-2159 // BID: 1416 // CNNVD: CNNVD-200006-117 // NVD: CVE-2000-0582

REFERENCES

url:http://www.securityfocus.com/bid/1416

Trust: 1.7

url:http://www.checkpoint.com/techsupport/alerts/list_vun.html#smtp_security

Trust: 1.7

url:http://www.osvdb.org/1438

Trust: 1.7

url:http://www.securityfocus.com/templates/archive.pike?list=1&msg=pine.lnx.3.96.1000630162106.4619c-100000%40fjord.fscinternet.com

Trust: 1.0

url:http://www.securityfocus.com/templates/archive.pike?list=1&msg=pine.lnx.3.96.1000630162106.4619c-100000@fjord.fscinternet.com

Trust: 0.7

url: -

Trust: 0.1

sources: VULHUB: VHN-2159 // CNNVD: CNNVD-200006-117 // NVD: CVE-2000-0582

CREDITS

Posted to BugTraq on June 30, 2000 in an advisory by SecureXpert Labs, in which the following individuals are credited: Mike Murray, Max Degtyar, and Richard Reiner, all of SecureXpert Labs.

Trust: 0.9

sources: BID: 1416 // CNNVD: CNNVD-200006-117

SOURCES

db:VULHUBid:VHN-2159
db:BIDid:1416
db:CNNVDid:CNNVD-200006-117
db:NVDid:CVE-2000-0582

LAST UPDATE DATE

2024-08-14T13:40:49.044000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-2159date:2008-09-10T00:00:00
db:BIDid:1416date:2000-06-30T00:00:00
db:CNNVDid:CNNVD-200006-117date:2006-01-04T00:00:00
db:NVDid:CVE-2000-0582date:2023-11-07T01:55:20.933

SOURCES RELEASE DATE

db:VULHUBid:VHN-2159date:2000-06-30T00:00:00
db:BIDid:1416date:2000-06-30T00:00:00
db:CNNVDid:CNNVD-200006-117date:2000-06-30T00:00:00
db:NVDid:CVE-2000-0582date:2000-06-30T04:00:00