Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

OpenSSL Vulnerability

26 March 2004

Recent OpenSSL advisories reveal vulnerabilities in OpenSSL versions 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, which may allow unauthenticated remote attackers to cause a denial of service. Applications or systems that use the OpenSSL SSL/TLS library (libssl) may be affected.

US-Cert TA04-078A
CAN-2004-0079
CAN-2004-0081
CAN-2004-0112
RHSA-2004:121-04

Affected Releases:

  • VPN-1/FireWall-1 NG and above
  • VPN-1/FireWall-1 VSX NG with Application Intelligence
  • Provider-1 NG and above
  • FireWall-1 GX v2.0

NOTE: VPN-1/FireWall-1 4.1 (all Service Packs) are NOT affected.

Check Point recommends that customers install an update on all management stations and enforcement modules in order to protect affected releases against the issues described in these advisories. Refer to the specific hotfix release notes for instructions.

These updates are available for Software Subscription customers from the links below:

VPN-1/FireWall-1 NG with Application Intelligence
R55 Hotfix HFA-02

R55 HFA-02 for IPSO
R55 HFA-02 for Linux
R55 HFA-02 for SecurePlatform
R55 HFA-02 for Solaris
R55 HFA-02 for Windows

VPN-1/FireWall-1 NG with Application Intelligence R54 OpenSSL Hotfix

R54 OpenSSL Hotfix for IPSO
R54 OpenSSL Hotfix for Linux
R54 OpenSSL Hotfix for SecurePlatform
R54 OpenSSL Hotfix for Solaris
R54 OpenSSL Hotfix for Windows

VPN-1/FireWall-1 NG FP3 OpenSSL Hotfix

FP3 OpenSSL Hotfix for IPSO
FP3 OpenSSL Hotfix for Linux
FP3 OpenSSL Hotfix for SecurePlatform
FP3 OpenSSL Hotfix for Solaris
FP3 OpenSSL Hotfix for Windows

VPN-1/FireWall-1 VSX NG with Application Intelligence

VPN-1/FireWall-1 VSX

Provider-1 NG with Application Intelligence R55 OpenSSL Hotfix

Provider-1 R55 OpenSSL Hotfix for Linux
Provider-1 R55 OpenSSL Hotfix for SecurePlatform
Provider-1 R55 OpenSSL Hotfix for Solaris

Provider-1 NG with Application Intelligence R54 OpenSSL Hotfix

Provider-1 R54 OpenSSL Hotfix for Linux
Provider-1 R54 OpenSSL Hotfix for Solaris

Provider-1 NG FP3 OpenSSL Hotfix

Provider-1 FP3 OpenSSL Hotfix for Solaris

FireWall-1 GX v2.0 OpenSSL Hotfix

GX v2.0 OpenSSL Hotfix for IPSO
GX v2.0 OpenSSL Hotfix for Linux
GX v2.0 OpenSSL Hotfix for SecurePlatform
GX v2.0 OpenSSL Hotfix for Solaris

OpenSSL Hotfixes will be included in future Hotfix Accumulator (HFA) releases for Next Generation FP3 and NG with Application Intelligence R54. Customers requesting a fix on these versions prior to the respective HFA releases should contact Check Point Technical Services for assistance.