Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortimail | 6.4.0 | 6.4.5 |
| fortinet / fortimail | 6.2.0 | 6.2.7 |
| fortinet / fortimail | - | 5.4.12.x |
| fortinet / fortimail | 5.6.1 | 6.0.11 |