A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-21-042 | Vendor Advisory |
https://fortiguard.com/advisory/FG-IR-21-042 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.com/advisory/FG-IR-21-042 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 5.3 |
Information
Published : 2021-07-12 13:15
Updated : 2024-11-21 05:55
NVD link : CVE-2021-26090
Mitre link : CVE-2021-26090
CVE.ORG link : CVE-2021-26090
JSON object : View
Products Affected
fortinet
- fortimail
CWE
CWE-401
Missing Release of Memory after Effective Lifetime