A double free vulnerability [CWE-415] in Fortinet FortiOS before 7.0.0 may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
The product calls free() twice on the same memory address.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortios | Fortinet | 6.2.0 (including) | 6.2.16 (including) |
Fortios | Fortinet | 6.4.0 (including) | 6.4.15 (including) |