Menu

#299 SECURITY: Windows installer subject to DLL Hijacking

Next_Nightly
fixed
None
Bug_Report
2016-02-17
2016-02-14
No

The current v16 Windows installer is built with NSIS 2.46 which suffers from a security vulnerability described here: https://textplain.wordpress.com/2015/12/18/dll-hijacking-just-wont-die/.

Please upgrade to NSIS2.5 to fix the issue.

Thanks!

Discussion

  • Morten MacFly

    Morten MacFly - 2016-02-14

    What installer(s) exactly? We have many of them and most should be using a way more recent NSIS.

     
  • Morten MacFly

    Morten MacFly - 2016-02-14
    • status: open --> pending
    • assigned_to: Morten MacFly
     
  • Eric Lawrence

    Eric Lawrence - 2016-02-16

    I tried both codeblocks-16.01-setup.exe and codeblocks-16.01mingw-setup.exe and both were built with the older NSIS. NSIS 2.5 was only released in December.

     
  • Morten MacFly

    Morten MacFly - 2016-02-17
    • status: pending --> fixed
     

Log in to post a comment.

MongoDB Logo MongoDB