PSIRT Advisories
Buffer overflow in TFTP client library of CLI
Summary
A buffer overflow [CWE-121] in the TFTP client library of FortiOS, FortiOS-6K7K, FortiADC, FortiAnalyzer, FortiManager, FortiNDR, FortiProxy, FortiSwitch, FortiWeb may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
Affected Products
FortiOS versions 6.0.13 and below,
FortiOS versions 6.2.9 and below,
FortiOS versions 6.4.7 and below,
FortiOS versions 7.0.2 and below.
FortiOS-6K7K 6.4.6 and 6.4.2.
FortiOS-6K7K 6.2.8 and below.
FortiADC version 5.0.4 and below,
FortiADC version 5.1.7 and below,
FortiADC version 5.2.8 and below,
FortiADC version 5.3.7 and below,
FortiADC version 5.4.5 and below,
FortiADC version 6.0.4 and below,
FortiADC version 6.1.5 and below,
FortiADC version 6.2.2 and below,
FortiAnalyzer version 6.0.0 through 6.0.11
FortiAnalyzer version 6.2.0 through 6.2.9
FortiAnalyzer version 6.4.0 through 6.4.7
FortiAnalyzer version 7.0.0 through 7.0.2
FortiManager version 6.0.11 and below,
FortiManager version 6.2.9 and below,
FortiManager version 6.4.7 and below,
FortiManager version 7.0.2 and below,
FortiNDR version 1.5.2 and below,
FortiNDR version 1.4.0 and below,
FortiNDR version 1.3.1 and below,
FortiNDR version 1.2.0 and below,
FortiNDR version 1.1.0 and below,
FortiProxy version 1.0.0 through 1.0.7
FortiProxy version 1.1.0 through 1.1.6
FortiProxy version 1.2.0 through 1.2.13
FortiProxy version 2.0.0 through 2.0.7
FortiProxy version 7.0.0 through 7.0.1
FortiSwitch version 6.0.7 and below,
FortiSwitch version 6.2.7 and below,
FortiSwitch version 6.4.9 and below,
FortiSwitch version 7.0.3 and below,
FortiWeb version 5.9.1 and below.
FortiWeb version 6.0.7 and below.
FortiWeb version 6.1.2 and below.
FortiWeb version 6.2.7 and below.
FortiWeb version 6.3.16 and below.
FortiWeb versions 6.4.1 and 6.4.0
Solutions
Upgrade to FortiOS 7.0.3 or above,
Upgrade to FortiOS 6.4.8 or above,
Upgrade to FortiOS 6.2.10 or above,
Upgrade to FortiOS 6.0.14 or above.
Upgrade to FortiOS-6K7K 6.2.9 or above.
Upgrade to FortiOS-6K7K 6.4.8 or above.
Upgrade to FortiADC 7.0.1 or above.
Upgrade to FortiADC 6.2.3 or above.
Upgrade to FortiADC 6.1.6 or above.
Upgrade to FortiAnalyzer 7.0.3 or above.
Upgrade to FortiAnalyzer 6.4.8 or above.
Upgrade to FortiManager 7.0.3 or above,
Upgrade to FortiManager 6.4.8 or above,
Upgrade to FortiNDR 7.0.0 or above,
Upgrade to FortiProxy 7.0.2 or above,
Upgrade to FortiProxy 2.0.8 or above,
Upgrade to FortiSwitch 7.2.0 or above.
Upgrade to FortiSwitch 7.0.4 or above.
Upgrade to FortiSwitch 6.4.10 or above.
Upgrade to FortiWeb 7.0.0 or above,
Upgrade to FortiWeb 6.4.2 or above,
Upgrade to FortiWeb 6.3.17 or above,