CVE-2016-6909: Buffer Overflow
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6909?
CVE-2016-6909 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2016-6909?
To fix CVE-2016-6909, upgrade FortiOS to version 4.1.11, 4.2.13, or 4.3.9 or higher, and FortiSwitch to version 3.4.3 or higher.
What systems are affected by CVE-2016-6909?
CVE-2016-6909 affects Fortinet FortiOS versions prior to 4.1.11, 4.2.13, and 4.3.9, as well as FortiSwitch versions up to 3.4.2.
What kind of attack does CVE-2016-6909 enable?
CVE-2016-6909 allows remote attackers to execute arbitrary code through a crafted HTTP request.
Who is responsible for addressing CVE-2016-6909?
Fortinet is responsible for releasing patches and updates to address the vulnerability CVE-2016-6909.