A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.
References
Link | Resource |
---|---|
https://fortiguard.com/advisory/FG-IR-21-042 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-07-12 13:15
Updated : 2021-07-13 19:26
NVD link : CVE-2021-26090
Mitre link : CVE-2021-26090
CVE.ORG link : CVE-2021-26090
JSON object : View
Products Affected
fortinet
- fortimail
CWE
CWE-401
Missing Release of Memory after Effective Lifetime