Re: nsis CVE-2023-37378

2023-07-09 Thread Salvatore Bonaccorso
hi Sean, hi Sylvain, On Sat, Jul 08, 2023 at 05:35:36PM +0200, Sylvain Beucler wrote: > Hi, > > On 08/07/2023 10:04, Sean Whitton wrote: > > On Sat 08 Jul 2023 at 09:14am +02, Salvatore Bonaccorso wrote: > > > > > Just noticed the suffix for the version for the buster-security / LTS > > >

Re: nsis CVE-2023-37378

2023-07-08 Thread Sylvain Beucler
Hi, On 08/07/2023 10:04, Sean Whitton wrote: On Sat 08 Jul 2023 at 09:14am +02, Salvatore Bonaccorso wrote: Just noticed the suffix for the version for the buster-security / LTS upload was +deb9u1, was this intentional? This should have been +deb10u1. It wasn't. Thank you for pointing out

Re: nsis CVE-2023-37378

2023-07-08 Thread Sean Whitton
Hello, On Sat 08 Jul 2023 at 09:14am +02, Salvatore Bonaccorso wrote: > Just noticed the suffix for the version for the buster-security / LTS > upload was +deb9u1, was this intentional? This should have been > +deb10u1. It wasn't. Thank you for pointing out the mistake. -- Sean Whitton

Re: nsis CVE-2023-37378

2023-07-08 Thread Salvatore Bonaccorso
Hi Sean, On Fri, Jul 07, 2023 at 01:07:57PM +0100, Sean Whitton wrote: > Hello, > > On Fri 07 Jul 2023 at 12:23pm +02, Sylvain Beucler wrote: > > > Hello Sean, > > > > I had a quick test with my: > > http://git.savannah.gnu.org/cgit/freedink.git/tree/nsis > > which is kinda old but does call

Re: nsis CVE-2023-37378

2023-07-07 Thread Sean Whitton
Hello, On Fri 07 Jul 2023 at 12:23pm +02, Sylvain Beucler wrote: > Hello Sean, > > I had a quick test with my: > http://git.savannah.gnu.org/cgit/freedink.git/tree/nsis > which is kinda old but does call WriteUninstaller. > The installer and uninstaller appear to work correctly in a W10 VM. > >

Re: nsis CVE-2023-37378

2023-07-07 Thread Sylvain Beucler
Hello Sean, I had a quick test with my: http://git.savannah.gnu.org/cgit/freedink.git/tree/nsis which is kinda old but does call WriteUninstaller. The installer and uninstaller appear to work correctly in a W10 VM. About the source changes, I'd recommend to use the CVE ID as part of the patch

nsis CVE-2023-37378

2023-07-06 Thread Sean Whitton
Hello, I've prepared an upload to buster-security [1] to fix CVE-2023-37378. I've tested it using an example script from [2], but if anyone reading has a real, production NSIS script, that includes an uninstaller, in particular, then testing my upload by using it to build your script would be