A double free vulnerability [CWE-415] in Fortinet FortiOS before 7.0.0 may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
Solution:
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://fortiguard.com/psirt/FG-IR-23-195 | vendor advisory |