Stack buffer overflow in CLI command

Summary

A stack-buffer overflow vulnerability [CWE-121] in FortiMail CLI may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.

Version Affected Solution
FortiMail 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiMail 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiMail 7.2 7.2.0 through 7.2.6 Upgrade to 7.2.7 or above
FortiMail 7.0 7.0 all versions Migrate to a fixed release
FortiMail 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally reported and discovered by Théo Leleu of Fortinet Product Security team.

Timeline

2025-03-11: Initial publication
2025-03-19: Added 7.2 solution