Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.2.14. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

1074460

Buffer overflow issues related to corrupted traffic log files, which could lead to a crash.

1111141

WAD process crashes continuously after ftgd-local-rating configuration.

1117526

list_entry should be typesafe.

1117013

wad_hash_cache timeout issue.

1112600

The wad_ftp_session_task_start does not initiate while establishing the data connection.

1005867, 1087631, 1088866 AV scan does not work for archived msoffice, msofficex and 7z files.
1054835, 1121171 Proxy HTTP2 single file transfer is slow when IPS/APP/SSL inspect-all is enabled.
924740 Improve WAD trace log precision of process-id-by-src filter.
1127033 IP pool is not updated after configuration change.
1119389 Explicit proxy does not work via IPsec tunnel.
1103476 License leak.
1128283 Logs that should have duration 0 sometimes show wrong values.
1094526, 1116906, 1126935 GUI issues.
1126862 Traffic is passed by transparent deny policy when log-http-transaction is enabled.
1133565 Password protected msofficex and msoffice files are bypassed when encrypted-file is set to inspect.
1126749 Duplicate session ID in traffic logs across different connections.

1102796

Passive proxy member send LDAP requests to the LDAP servers.

1140953

HTTP2 large file download may get stuck and fail.

1149807 Policy lookup tool does not match source interface.

1144421

ICAP crash.

1130882 Missing field details in http-transaction logs for deep-inspect https CONNECT traffic.

1135096

In HTTP transaction log, when certificate inspection is set, the URL filed lost protocol information if traffic passes through.

1095093, 1092529 "utmref" and "utmaction" fields are missing in forward traffic log and long-tcp sessions are missing in http-transaction traffic log.

1102694

"utmref" and "utmaction" fields are missing in forward traffic log and http-transaction

traffic log for long-tcp sessions.

1157551

Memory leak caused by missing put after wad_str_assign.

859182

WAD crashed at fts_crypto_kxp_pub_key_verify_done.

1012811 Log time is one hour behind NTP after daylight savings time change.

1114438

Policy test feature does not work when no WAD debug is running in the background.

1162152

When setting system time in GUI, the Time field should not include the millisecond value.

Common vulnerabilities and exposures

FortiProxy 7.2.14 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

1121042

CVE-2024-52965

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.2.14. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

1074460

Buffer overflow issues related to corrupted traffic log files, which could lead to a crash.

1111141

WAD process crashes continuously after ftgd-local-rating configuration.

1117526

list_entry should be typesafe.

1117013

wad_hash_cache timeout issue.

1112600

The wad_ftp_session_task_start does not initiate while establishing the data connection.

1005867, 1087631, 1088866 AV scan does not work for archived msoffice, msofficex and 7z files.
1054835, 1121171 Proxy HTTP2 single file transfer is slow when IPS/APP/SSL inspect-all is enabled.
924740 Improve WAD trace log precision of process-id-by-src filter.
1127033 IP pool is not updated after configuration change.
1119389 Explicit proxy does not work via IPsec tunnel.
1103476 License leak.
1128283 Logs that should have duration 0 sometimes show wrong values.
1094526, 1116906, 1126935 GUI issues.
1126862 Traffic is passed by transparent deny policy when log-http-transaction is enabled.
1133565 Password protected msofficex and msoffice files are bypassed when encrypted-file is set to inspect.
1126749 Duplicate session ID in traffic logs across different connections.

1102796

Passive proxy member send LDAP requests to the LDAP servers.

1140953

HTTP2 large file download may get stuck and fail.

1149807 Policy lookup tool does not match source interface.

1144421

ICAP crash.

1130882 Missing field details in http-transaction logs for deep-inspect https CONNECT traffic.

1135096

In HTTP transaction log, when certificate inspection is set, the URL filed lost protocol information if traffic passes through.

1095093, 1092529 "utmref" and "utmaction" fields are missing in forward traffic log and long-tcp sessions are missing in http-transaction traffic log.

1102694

"utmref" and "utmaction" fields are missing in forward traffic log and http-transaction

traffic log for long-tcp sessions.

1157551

Memory leak caused by missing put after wad_str_assign.

859182

WAD crashed at fts_crypto_kxp_pub_key_verify_done.

1012811 Log time is one hour behind NTP after daylight savings time change.

1114438

Policy test feature does not work when no WAD debug is running in the background.

1162152

When setting system time in GUI, the Time field should not include the millisecond value.

Common vulnerabilities and exposures

FortiProxy 7.2.14 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

1121042

CVE-2024-52965