Stack-based buffer overflows in API controllers
Summary
Multiple stack-based buffer overflows [CWE-121] in the API controllers of FortiWeb may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.
Affected Products
FortiWeb version 6.4.1 and earlier.
FortiWeb version 6.3.15 and earlier.
Solutions
Upgrade to FortiWeb version 7.0.0 and later.
Upgrade to FortiWeb version 6.4.2 and later.
Upgrade to FortiWeb version 6.3.16 and later.
Acknowledgement
Internally discovered and reported by Giuseppe Cocomazzi of the Fortinet Product Security team.Timeline
2021-12-07: Initial publication