CVE-2015-7362: High severity fortinet forticlient vulnerability
Published Jan 8, 2016
·Updated
Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc setuid program.
Affected Software
1 affected component
Fortinet Forticlient Linux Kernel
Event History
Jan 8, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7362?
CVE-2015-7362 is rated as a high-severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2015-7362?
To fix CVE-2015-7362, ensure that FortiClient is upgraded to a version that is 2313 or later.
3
What type of vulnerability is CVE-2015-7362?
CVE-2015-7362 is a local privilege escalation vulnerability affecting the FortiClient SSLVPN on Linux.
4
Who is affected by CVE-2015-7362?
Users of Fortinet FortiClient SSLVPN on Linux installed in a world-readable and executable home directory are affected by CVE-2015-7362.
5
What version of FortiClient is impacted by CVE-2015-7362?
Fortinet FortiClient Linux SSLVPN before build 2313 is impacted by CVE-2015-7362.