CVE-2019-16152
Summary
| CVE | CVE-2019-16152 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-06 16:15:00 UTC |
| Updated | 2020-02-12 18:35:00 UTC |
| Description | A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes running under root privilege crashes via sending specially crafted IPC client requests to the fctsched process due the nanomsg not been correctly validated. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Forticlient | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple privilege escalations in FortiClient for Linux | Danish Cyber Defence | MISC | danishcyberdefence.dk | Exploit, Third Party Advisory |
| Privilege escalation and DoS in FortiClient for Linux through local IPC socket | FortiGuard | CONFIRM | fortiguard.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.