Unrated severityNVD Advisory· Published Jul 3, 2023· Updated Sep 5, 2024
CVE-2023-37378
CVE-2023-37378
Description
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
9- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A65FBUMHLZ7GBV3VDKUB5EK3A7X2UUWK/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OZPAAU57IA3NP6UOUXNBUQBAYK3JB2IM/mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/07/msg00005.htmlmitremailing-list
- sf.net/p/nsis/bugs/1296mitre
- github.com/kichik/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967mitre
- github.com/kichik/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467mitre
- github.com/kichik/nsis/commit/c40cf78994e74a1a3a381a850c996b251e3277c0mitre
- nsis.sourceforge.io/Docs/AppendixF.htmlmitre
- sourceforge.net/p/nsis/news/2023/07/nsis-309-released/mitre
News mentions
0No linked articles in our index yet.