CVE-2023-37378 Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3874-1
Update to 3.09, fixes CVE-2023-37378.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-dfb6cc599f 2023-07-13 01:28:20.305595 --------------------------------------------------------------------------------Name : mingw-nsis Product : Fedora 38 Version : 3.09 Release : 1.fc38 URL : https://nsis.sourceforge.io/Main_Page Summary : Nullsoft Scriptable Install System Description : NSIS, the Nullsoft Scriptable Install System, is a script-driven Windows installation system. This package includes native Fedora binaries of makensis (etc.) and all plugins. --------------------------------------------------------------------------------Update Information: Update to 3.09, fixes CVE-2023-37378. --------------------------------------------------------------------------------ChangeLog: * Tue Jul 4 2023 Sandro Mani - 3.09-1 - Update to 3.09 --------------------------------------------------------------------------------References: [ 1 ] Bug #2219513 - CVE-2023-37378 mingw-nsis: nsis: mishandles access control for an uninstaller directory [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2219513 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-dfb6cc599f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that the Nullsoft Scriptable Install System (NSIS) before version 3.09 mishandles access control for the uninstaller directory. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3483-1
Get the latest Linux and open source security news straight to your inbox.