[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-disclosure] Layered Defense Research Advisory: Format String Vulnerability: FortiClient Version 3



Layered Defense Research Advisory 02 April 2009
==================================================
1) Affected Product
FortiClient Version 3.0.614
Earlier versions may also be vulnerable
==================================================
2) Severity Rating: Low
==================================================
3) Description of Vulnerability:
A local format string vulnerability was discovered within FortiClient 
version 3.0.614 VPN .The vulnerability is due to improper processing 
of format strings specifiers within the VPN connection name. When 
special crafted format strings are entered as the VPN connection name 
and the connection is initiated the format string vulnerability is 
triggered. Making it possible to read and write arbitrary memory at 
System level.
==================================================
4) Solution : Upgrade to FortiClient v3.0 MR7 Patch Release 6
==================================================
5) Time Table:
02/02/2009 Reported Vulnerability to Vendor.
02/03/2009 Vendor acknowledged the vulnerability
03/13/2009 Vendor published fix
==================================================
6) Credits Discovered by Deral Heiland, www.LayeredDefense.com
==================================================
7) Reference
https://support.fortinet.com/Login/UserLogin.aspx
==================================================
8) About Layered Defense Layered Defense, Is a group of security 
professionals that work together on ethical Research, Testing and 
Training within the information security arena. http://www.layereddefense.com
================================================== 

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/