Stack-based buffer overflows in API controllers

Summary

Multiple stack-based buffer overflows [CWE-121] in the API controllers of FortiWeb may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.

Affected Products

FortiWeb version 6.4.1 and earlier.
FortiWeb version 6.3.15 and earlier.

Solutions

Upgrade to FortiWeb version 7.0.0 and later.
Upgrade to FortiWeb version 6.4.2 and later.
Upgrade to FortiWeb version 6.3.16 and later.

Acknowledgement

Internally discovered and reported by Giuseppe Cocomazzi of the Fortinet Product Security team.

Timeline

2021-12-07: Initial publication