First published: Tue Apr 07 2009(Updated: )
Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string specifiers in the VPN connection name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiClient Virtual Private Network | =3.0.614 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1262 has a medium severity rating due to the potential for local users to execute arbitrary code.
To fix CVE-2009-1262, upgrade to Fortinet FortiClient version 3.0.615 or later where the vulnerability is resolved.
CVE-2009-1262 affects local users of Fortinet FortiClient version 3.0.614 and possibly earlier versions.
CVE-2009-1262 allows local users to execute arbitrary code via format string specifiers in the VPN connection name.
CVE-2009-1262 is a local vulnerability, meaning it requires local access to the affected system to exploit.