Uncontrolled memory allocation

Summary

A memory allocation with excessive size value vulnerability [CWE-789] in the license verification function of FortiPortal may allow an attacker to perform a denial of service attack via specially crafted license blobs.

Affected Products

FortiPortal versions 6.0.5 and below.
FortiPortal versions 5.3.6 and below.
FortiPortal versions 5.2.6 and below.
FortiPortal versions 5.1.2 and below.
FortiPortal versions 5.0.3 and below.
FortiPortal versions 4.2.2 and below.
FortiPortal versions 4.2.2 and below.
FortiPortal versions 4.1.2 and below.
FortiPortal versions 4.0.4 and below.

Solutions

Upgrade to FortiPortal version 7.0.0 or above.
Upgrade to FortiPortal version 6.0.6 or above.

Acknowledgement

Internally discovered and reported by Giuseppe Cocomazzi of Fortinet Product Security team.

Timeline

2021-11-02: Initial publication