Heap buffer overflow in httpd

Summary

A heap-based buffer overflow vulnerability [CWE-122] in FortiManager and FortiAnalyzer httpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands as a low priivileged user via specifically crafted requests.

Version Affected Solution
FortiAnalyzer 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiAnalyzer 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer 6.4 6.4 all versions Migrate to a fixed release
FortiAnalyzer Cloud 7.4 7.4.1 through 7.4.2 Upgrade to 7.4.3 or above
FortiAnalyzer Cloud 7.2 7.2.1 through 7.2.6 Upgrade to 7.2.7 or above
FortiAnalyzer Cloud 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer Cloud 6.4 6.4 all versions Migrate to a fixed release
FortiManager Cloud 7.0 Cloud 7.0 all versions Migrate to a fixed release
FortiManager Cloud 6.4 Cloud 6.4 all versions Migrate to a fixed release
FortiManager 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiManager 7.4 Cloud 7.4.1 through 7.4.2 Upgrade to 7.4.3 or above
FortiManager 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiManager 7.2 Cloud 7.2.1 through 7.2.6 Upgrade to 7.2.7 or above
FortiManager 7.0 7.0 all versions Migrate to a fixed release
FortiManager 6.4 6.4 all versions Migrate to a fixed release
FortiManager 6.2 6.2 all versions Migrate to a fixed release
FortiManager 6.0 6.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Timeline

2024-11-12: Initial publication
2024-11-15: corrected FMG Cloud 7.2.x fixed version