ELA-891-1 nsis security update

Mishandling of directory access control

2023-07-11
Packagensis
Version2.51-1+deb9u1
Related CVEs CVE-2023-37378


It was discovered that the Nullsoft Scriptable Install System (NSIS) before version 3.09 mishandles access control for the uninstaller directory.



For Debian 9 stretch, these problems have been fixed in version 2.51-1+deb9u1.

We recommend that you upgrade your nsis packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.