CVE-2020-29016

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:23

Type Values Removed Values Added
References () https://www.fortiguard.com/psirt/FG-IR-20-125 - Vendor Advisory () https://www.fortiguard.com/psirt/FG-IR-20-125 - Vendor Advisory

Information

Published : 2021-01-14 16:15

Updated : 2024-11-21 05:23


NVD link : CVE-2020-29016

Mitre link : CVE-2020-29016

CVE.ORG link : CVE-2020-29016


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-787

Out-of-bounds Write