First published: Tue Nov 27 2018(Updated: )
An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | <=5.2.12 | |
Fortinet FortiOS IPS Engine | >=5.4.6<=5.4.7 | |
Fortinet FortiOS IPS Engine | >=5.6.1<=5.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13376 has been classified with a medium severity level due to the potential exposure of sensitive data.
To mitigate CVE-2018-13376, upgrade to FortiOS version 5.6.4 or later, or 5.4.8 or later as applicable.
CVE-2018-13376 affects FortiOS versions 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, and all versions of 5.2.
CVE-2018-13376 may lead to sensitive data being leaked through the HTTP response due to an uninitialized memory buffer.
Currently, upgrading to a non-affected version is the recommended approach, as there are no detailed workarounds provided.