CVE-2023-29081

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:flexera:installshield:2016:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:sp2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2017:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2017:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:r3:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r3:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r3sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2021:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2021:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2022:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2022:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2023:r1:*:*:*:*:*:*

History

01 Feb 2024, 20:59

Type Values Removed Values Added
CPE cpe:2.3:a:flexera:installshield:2019:r3:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2021:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2022:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r3:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r3sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2017:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2023:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:sp2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2021:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2022:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2017:sp1:*:*:*:*:*:*
First Time Flexera installshield
Flexera
References () https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2023-29081-InstallShield-Symlink-Vulnerability-Affecting/ta-p/305052 - () https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2023-29081-InstallShield-Symlink-Vulnerability-Affecting/ta-p/305052 - Third Party Advisory
Summary
  • (es) Se ha informado de una vulnerabilidad en Suite Setups creadas con versiones anteriores a InstallShield 2023 R2. Esta vulnerabilidad puede permitir que los usuarios autenticados localmente provoquen una condición de denegación de servicio (DoS) al manejar operaciones de movimiento en carpetas locales temporales.

26 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-26 20:15

Updated : 2024-02-01 20:59


NVD link : CVE-2023-29081

Mitre link : CVE-2023-29081

CVE.ORG link : CVE-2023-29081


JSON object : View

Products Affected

flexera

  • installshield
CWE
CWE-276

Incorrect Default Permissions