CVE-2023-29081

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:flexera:installshield:2016:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:sp2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2017:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2017:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:r3:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r3:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r3sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2021:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2021:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2022:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2022:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2023:r1:*:*:*:*:*:*

History

21 Nov 2024, 07:56

Type Values Removed Values Added
References () https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2023-29081-InstallShield-Symlink-Vulnerability-Affecting/ta-p/305052 - Third Party Advisory () https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2023-29081-InstallShield-Symlink-Vulnerability-Affecting/ta-p/305052 - Third Party Advisory

01 Feb 2024, 20:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:flexera:installshield:2016:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:sp2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:r3:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2016:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r3sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2017:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2021:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2019:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2022:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2021:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2023:r1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r3:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2020:r2:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2018:sp1:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2017:-:*:*:*:*:*:*
cpe:2.3:a:flexera:installshield:2022:r1:*:*:*:*:*:*
First Time Flexera installshield
Flexera
CWE CWE-276
References () https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2023-29081-InstallShield-Symlink-Vulnerability-Affecting/ta-p/305052 - () https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2023-29081-InstallShield-Symlink-Vulnerability-Affecting/ta-p/305052 - Third Party Advisory

26 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-26 20:15

Updated : 2024-11-21 07:56


NVD link : CVE-2023-29081

Mitre link : CVE-2023-29081

CVE.ORG link : CVE-2023-29081


JSON object : View

Products Affected

flexera

  • installshield
CWE
CWE-276

Incorrect Default Permissions