Memory leak in FortiMail Webmail

Summary

A missing release of memory after its effective lifetime vulnerability (CWE-401) in FortiMail Webmail may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.

Affected Products

FortiMail 6.4.4 and below,
FortiMail 6.2.6 and below.

Solutions

Upgrade to FortiMail 7.0.0.
Upgrade to FortiMail 6.4.5.

Acknowledgement

Internally discovered and reported by Giuseppe Cocomazzi of the Fortinet PSIRT Team.