[<prev] [next>] [day] [month] [year] [list]
Message-Id: <20090402023546.0910615C@lists.grok.org.uk>
Date: Wed, 01 Apr 2009 22:28:40 -0400
From: Deral Heiland <dh@...ereddefense.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Layered Defense Research Advisory: Format String
Vulnerability: FortiClient Version 3
Layered Defense Research Advisory 02 April 2009
==================================================
1) Affected Product
FortiClient Version 3.0.614
Earlier versions may also be vulnerable
==================================================
2) Severity Rating: Low
==================================================
3) Description of Vulnerability:
A local format string vulnerability was discovered within FortiClient
version 3.0.614 VPN .The vulnerability is due to improper processing
of format strings specifiers within the VPN connection name. When
special crafted format strings are entered as the VPN connection name
and the connection is initiated the format string vulnerability is
triggered. Making it possible to read and write arbitrary memory at
System level.
==================================================
4) Solution : Upgrade to FortiClient v3.0 MR7 Patch Release 6
==================================================
5) Time Table:
02/02/2009 Reported Vulnerability to Vendor.
02/03/2009 Vendor acknowledged the vulnerability
03/13/2009 Vendor published fix
==================================================
6) Credits Discovered by Deral Heiland, www.LayeredDefense.com
==================================================
7) Reference
https://support.fortinet.com/Login/UserLogin.aspx
==================================================
8) About Layered Defense Layered Defense, Is a group of security
professionals that work together on ethical Research, Testing and
Training within the information security arena. http://www.layereddefense.com
==================================================
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists