Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
2018-10-01T08:29:00.413
2024-11-21T02:40:12.760
Modified
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nullsoft | nullsoft_scriptable_install_system | < 2.49 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |