| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi all, i just update SD on my NGX R60 HF03 SPLAT. I checked the "Block HTML Decoding Memmory Corruption Vulnerability" on the WI/Http Client Protections/Internet Explorer page and internet browsing stopped working well. For example the www.google.com page doesn't load anymore. Unchecking the box and recompiling the policies makes browsing work again. I went to the CP's SD web site to finde more info about this control and i don't find its description. Does anyone have this problem? Thanks Strion. |
| |||
| Did you patch your system? http://www.microsoft.com/technet/sec.../MS06-046.mspx Also may be you need patch http://www.microsoft.com/technet/sec.../MS06-021.mspx HTML Decoding Memory Corruption Vulnerability (CVE-2006-2382) - http://www.cve.mitre.org/cgi-bin/cve...=CVE-2006-2382. Last edited by kva.kva; 2006-09-15 at 07:50. |
| |||
| What difference will it make by having the fix installed? Support asked me exactly the same thing... "do all systems have the patch installed?" ticket is still open and it's been over a week. I had to disable MS06-046, even tough the logs showed the problem to be the "create TextRange" vulnerability. Problem is SD is somehow blocking traffic it shouldn't block, this isn't the first time SD has undesirable side effects for me. |
| |||
| Quote:
Out of curiosity, are the patched clients able to function properly with MS06-046 enabled? __________________ Its all in the documentation. |
| |||
| Quote:
They were able to duplicate the problem, but I'm still waiting for a solution. |
![]() |
| Thread Tools | |
| Display Modes | |
| |