CVE-2015-9268: Input Validation
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9268?
CVE-2015-9268 has been rated as a moderate severity vulnerability due to its potential security risks.
How do I fix CVE-2015-9268?
To fix CVE-2015-9268, upgrade to Nullsoft Scriptable Install System version 2.49 or later.
What are the consequences of CVE-2015-9268?
CVE-2015-9268 may allow an attacker to exploit unsafe implicit linking and potentially execute arbitrary code.
Which versions are affected by CVE-2015-9268?
CVE-2015-9268 affects Nullsoft Scriptable Install System versions prior to 2.49 and Debian Linux version 8.0.
Is CVE-2015-9268 related to any specific software?
CVE-2015-9268 specifically affects the Nullsoft Scriptable Install System and certain Debian Linux installations.