QID 44136
Date Published: 2023-11-29
QID 44136: FortiOS Multiple Vulnerabilities (FG-IR-23-385)
CVE-2023-38545:
A heap-based buffer overflow flaw was found in the SOCKS5 proxy handshake in the Curl package.s.
CVE-2023-38546:
A flaw was found in the Curl package. This flaw allows an attacker to insert cookies into a running program using libcurl if the specific series of conditions are met.
Affected Products:
The following products are impacted:
FortiGate (Only FGT_VM64 model is impacted and authentication is required)
FGT_VM64 version 7.4.0 through 7.4.1
FGT_VM64 version 7.2.0 through 7.2.6
FGT_VM64 version 7.0.1 through 7.0.13
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-385
- FG-IR-23-385 -
www.fortiguard.com/psirt/FG-IR-23-385
CVEs related to QID 44136
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-385 |
|