Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://fortiguard.com/advisory/FG-IR-21-152 | patch vendor advisory |