Stack based buffer overflow in httpd

Summary

A stack-based overflow vulnerability [CWE-124] in FortiManager & FortiAnalyzer may allow a remote attacker to execute arbitrary code or command as a low privileged user via specially crafted packets

Version Affected Solution
FortiAnalyzer 7.6 Not affected Not Applicable
FortiAnalyzer 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiAnalyzer 7.0 7.0.0 through 7.0.12 Upgrade to 7.0.13 or above
FortiAnalyzer 6.4 6.4.0 through 6.4.14 Upgrade to 6.4.15 or above
FortiAnalyzer Cloud 7.4 7.4.1 through 7.4.3 Upgrade to 7.4.4 or above
FortiAnalyzer Cloud 7.2 7.2.1 through 7.2.5 Upgrade to 7.2.6 or above
FortiAnalyzer Cloud 7.0 7.0.1 through 7.0.11 Upgrade to 7.0.12 or above
FortiAnalyzer Cloud 6.4 6.4 all versions Migrate to a fixed release
FortiManager 7.6 Not affected Not Applicable
FortiManager 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiManager 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiManager 7.0 7.0.0 through 7.0.12 Upgrade to 7.0.13 or above
FortiManager 6.4 6.4.0 through 6.4.14 Upgrade to 6.4.15 or above
FortiManager Cloud 7.4 7.4.1 through 7.4.3 Upgrade to 7.4.4 or above
FortiManager Cloud 7.2 7.2.1 through 7.2.5 Upgrade to 7.2.6 or above
FortiManager Cloud 7.0 7.0.1 through 7.0.11 Upgrade to 7.0.12 or above
FortiManager Cloud 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security Team.

Timeline

2025-01-14: Initial publication