[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1602-1] nsis security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : nsis
Version        : 2.46-10+deb8u1
CVE ID         : CVE-2015-9267 CVE-2015-9268


Among others, Andre Heinicke from gpg4win.org found several issues of nsis, a tool for creating quick and user friendly installers for
Microsoft Windows operating systems.

The issues are fixed by ...
  ... using SetDefaultDllDirectories() to restrict implicitly loaded
      and dynamically loaded modules to trusted directories
  ... creating temporary directories in a way that only elevated users
      can write into it
  ... not implicitly linking against Version.dll but using wrapper
      functions


For Debian 8 "Jessie", these problems have been fixed in version
2.46-10+deb8u1.

We recommend that you upgrade your nsis packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAlwBuiJfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEfbNw/9GmDMw7fhxaWgNQbz/b1RRhfMs8BBxBZBdMe3w5OrbxjkRTYJaQVrhAhH
CpNWcz90BmXjRyHOczP6EV8Uc0KTNFPEZKqnDSjZuAQiN3yGKwLzmrZn7x9Z48C4
YqExAgQHwKpjQcMhX3CgOONJqHHXPDmiCe1b2xrn72+XNkNjSCvyKY53aP/MDS6O
TZg9y9qQXaa4mjOSGFFpY+gpLo02c8g+Tx4r1534BomQgykHd99e1mD0dS9m+jH6
0y+0IFNLujoZDpiyCQ1dqSveHhDyDCWNjtNgSAP64lSV/iTVyCWXZOfLaJhj4a1w
FYUqnr4V2diiwKEV2WgOC0TjUlHFe+Z9yIqs/S6+ByNRTuy3ooPPkoSZVcGL8Nvv
R2m1RkGXjpZeZmfjiIpH2N7WA5NPiMlhj9NHhd3Zqu1kWYh/CnI+XnCQTC7b9m1Z
7tx0mx51TxiHHTZnb0NEuBUPe0WcnoFdlkqrl8GURAG8OVnp7lPqQBkPTVkz2q5c
GE4M3cB8tdjDTKc0Jp9lUgISSIAyEOf5ygvA14zaa9+jdItBK8Z4FFYJf6D7Piqt
50z9mMpsoG5R47BJaVsOe1Rre+1Csj/JdGfcc7dxER2Nz7naDPtGMhpK9MOADCYT
Gl5FBM23qxzzKrs+DDS4nSXu+M6LTBsfJHKVHuuIujL8Q8qRnmc=
=+r1R
-----END PGP SIGNATURE-----


Reply to: