Описание
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-6909
- https://musalbas.com/2016/08/16/equation-group-firewall-operations-catalogue.html
- https://www.exploit-db.com/exploits/40276
- http://fortiguard.com/advisory/FG-IR-16-023
- http://packetstormsecurity.com/files/138387/EGREGIOUSBLUNDER-Fortigate-Remote-Code-Execution.html
- http://www.securityfocus.com/bid/92523
- http://www.securitytracker.com/id/1036643
Связанные уязвимости
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
Уязвимость операционной системы FortiOS и микропрограммного обеспечения сетевых коммутаторов FortiSwitch, позволяющая нарушителю выполнить произвольный код