<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulerability#CVE-2007-4752 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35375#M7461</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sk65269 also gives a command to check the vulnerability of the installed openssh binary...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Oct 2018 10:55:46 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-10-15T10:55:46Z</dc:date>
    <item>
      <title>Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35373#M7459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are getting the below vulnerability for the checkpoint. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name : OpenSSH X11 Cookie Local Authentication Bypass Vulnerability (openssh-x11-cookie-auth-bypass)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Description :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;OpenBSD OpenSSH &amp;lt; 4.7&lt;BR /&gt;&lt;SPAN&gt;Download and apply the upgrade from: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH" rel="nofollow"&gt;ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH&lt;/A&gt;&lt;BR /&gt;While you can always build OpenSSH from source, many platforms and distributions provide pre-built binary packages for OpenSSH.&lt;BR /&gt;These pre-built packages are usually customized and optimized for a particular distribution, therefore we recommend that you use the packages if they are available for your operating system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the take installed is take_286.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the above description, I can find the CVE associated for the vulnerability is #CVE-2007-4752.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the #sk65269, I can see the comments given is Not vulnerable. So it means checkpoint devices are not vulnerable for this vulnerbaility ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vengatesh SR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 10:32:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35373#M7459</guid>
      <dc:creator>Vengatesh_SR</dc:creator>
      <dc:date>2018-10-15T10:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35374#M7460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you can find your reply , have fun&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65269&amp;amp;partition=General&amp;amp;product=All%22" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65269&amp;amp;partition=General&amp;amp;product=All%22"&gt;Status of OpenSSH CVEs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 10:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35374#M7460</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2018-10-15T10:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35375#M7461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sk65269 also gives a command to check the vulnerability of the installed openssh binary...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 10:55:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35375#M7461</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-10-15T10:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35376#M7462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SK is pretty clear--not vulnerable.&lt;/P&gt;&lt;P&gt;In general, this can be because:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Our configuration does not include the relevant code needed to exploit the vulnerability&lt;/LI&gt;&lt;LI&gt;We've patched the relevant defect&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 11:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35376#M7462</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-15T11:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35377#M7463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So it means our devices are not vulnerable right ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 11:43:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35377#M7463</guid>
      <dc:creator>Vengatesh_SR</dc:creator>
      <dc:date>2018-10-15T11:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35378#M7464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, not vulnerable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 11:46:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35378#M7464</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-15T11:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35379#M7465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow Great!!! Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 12:27:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35379#M7465</guid>
      <dc:creator>Vengatesh_SR</dc:creator>
      <dc:date>2018-10-15T12:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35380#M7466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 12:53:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/35380#M7466</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-10-15T12:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Vulerability#CVE-2007-4752</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/65107#M13306</link>
      <description>&lt;P&gt;Do we have a way to prove that we're not vulnerable?&amp;nbsp; &amp;nbsp;We are using a Rapid7 scanner, and it is seeing the vulnerability and we need to show evidence that the vulnerability does not exist rather than just an sk that says "not vulnerable".&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 12:58:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Vulerability-CVE-2007-4752/m-p/65107#M13306</guid>
      <dc:creator>tbindenagel</dc:creator>
      <dc:date>2019-10-16T12:58:10Z</dc:date>
    </item>
  </channel>
</rss>

