Medium severity5.3NVD Advisory· Published Jul 3, 2023· Updated Jun 17, 2026
CVE-2023-37378
CVE-2023-37378
Description
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<3.09+ 2 more
- (no CPE)range: <3.09
- (no CPE)
- cpe:2.3:a:nullsoft:nullsoft_scriptable_install_system:*:*:*:*:*:*:*:*range: <=3.09
Patches
Vulnerability mechanics
References
10- github.com/kichik/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967nvdPatch
- github.com/kichik/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467nvdPatch
- github.com/kichik/nsis/commit/c40cf78994e74a1a3a381a850c996b251e3277c0nvdPatch
- lists.debian.org/debian-lts-announce/2023/07/msg00005.htmlnvdMailing ListThird Party Advisory
- sf.net/p/nsis/bugs/1296nvdIssue TrackingPermissions Required
- nsis.sourceforge.io/Docs/AppendixF.htmlnvdRelease Notes
- sourceforge.net/p/nsis/news/2023/07/nsis-309-released/nvdRelease Notes
- lists.debian.org/debian-lts-announce/2024/09/msg00013.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A65FBUMHLZ7GBV3VDKUB5EK3A7X2UUWK/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OZPAAU57IA3NP6UOUXNBUQBAYK3JB2IM/nvd
News mentions
0No linked articles in our index yet.