CVE-2019-17652
Summary
| CVE | CVE-2019-17652 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-06 16:15:00 UTC |
| Updated | 2020-02-12 18:36:00 UTC |
| Description | A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted "StartAvCustomScan" type IPC client requests to the fctsched process due the argv data not been well sanitized. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Forticlient | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple privilege escalations in FortiClient for Linux | Danish Cyber Defence | MISC | danishcyberdefence.dk | Exploit, Third Party Advisory |
| Privilege escalation and DoS in FortiClient for Linux through local IPC socket | FortiGuard | CONFIRM | fortiguard.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.