{"id":"CVE-2023-37378","details":"Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.","modified":"2026-08-12T13:32:40.079910Z","published":"2023-07-03T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37378.json","unresolved_ranges":[{"extracted_events":[{"fixed":"3.09"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"http://sf.net/p/nsis/bugs/1296"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00013.html"},{"type":"WEB","url":"https://nsis.sourceforge.io/Docs/AppendixF.html#v3.09"},{"type":"WEB","url":"https://sourceforge.net/p/nsis/news/2023/07/nsis-309-released/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37378.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A65FBUMHLZ7GBV3VDKUB5EK3A7X2UUWK/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OZPAAU57IA3NP6UOUXNBUQBAYK3JB2IM/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37378"},{"type":"FIX","url":"https://github.com/kichik/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967"},{"type":"FIX","url":"https://github.com/kichik/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467"},{"type":"FIX","url":"https://github.com/kichik/nsis/commit/c40cf78994e74a1a3a381a850c996b251e3277c0"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/07/msg00005.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nsis-dev/nsis","events":[{"introduced":"0"},{"fixed":"281e2851fe669d10e0650fc89d0e7fb74a598967"},{"fixed":"409b5841479c44fbf33a6ba97c1146e46f965467"},{"fixed":"c40cf78994e74a1a3a381a850c996b251e3277c0"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v308","v307","v3061","v306","v305","v304","v303","v3021","v301","v30","v30rc2","v30rc1","v30b3","v30b2","v30b1","v30b0","v30a2","v30a1","v246","v245","v244","v243","v242","v241","v240","v239","v238","v237","v236","v235","v234","v233","v232","v231","v230","v229","v228","v227","v226","v225","v224","v223","v222","v221","v220","v219","v218","v217","v216","v215","v214","v213","v212","v211","v210","v208","v207","v207b0","v206","v205","v204","v203","v202","v201","v20","v20rc4","v20rc3","v20rc2","v20rc1","v20b4","v20b3","v20b2","v20b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37378.json","vanir_signatures_modified":"2026-08-12T13:32:40Z","vanir_signatures":[{"source":"https://github.com/nsis-dev/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467","target":{"file":"Source/exehead/util.c"},"deprecated":false,"digest":{"line_hashes":["324958057323643130586345113791539764096","117616857455475812510142102486678823590","324850355286303962528828379944142614501","94954054456980137786801492744165139778"],"threshold":0.9},"id":"CVE-2023-37378-1f336d60","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/nsis-dev/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967","target":{"file":"Source/exehead/util.c","function":"CreateRestrictedDirectory"},"deprecated":false,"digest":{"function_hash":"245933394105413283240663427846959844977","length":522},"id":"CVE-2023-37378-3ed50a8d"},{"target":{"file":"Source/exehead/util.c"},"deprecated":false,"digest":{"line_hashes":["326141712043076416526136596523430540743","202982482643067989298280844419095220382","24263019519671736427181619813841818864","189704634293646577263530309866634631379","3146274400194407823793192805166777700","322755437027658954649796029100613919458","85661416849814806130203934723416872477","51215092847227404712084550922762011336","313717456832945400106721311441839891853","57510050877321720187454097656411127526","98686635033574899021195805781878172080"],"threshold":0.9},"id":"CVE-2023-37378-66428610","signature_type":"Line","signature_version":"v1","source":"https://github.com/nsis-dev/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/nsis-dev/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967","target":{"file":"Source/build.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["330747107025817459460812397665623240370","192542784115639272777968930244041434538","28918449838761000964390576299328945104","140309671072166091083619161475956417937","192913407631971418116817235182798046963"]},"id":"CVE-2023-37378-9a95f4f9"},{"deprecated":false,"digest":{"function_hash":"268958813105703448559889959580320807284","length":7120},"id":"CVE-2023-37378-a9a8ad41","signature_type":"Function","signature_version":"v1","source":"https://github.com/nsis-dev/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967","target":{"file":"Source/exehead/Main.c","function":"NSISWinMainNOCRT"}},{"target":{"file":"Source/build.cpp","function":"CEXEBuild::AddStandardStrings"},"deprecated":false,"digest":{"length":496,"function_hash":"216184667392552618939447548904334110197"},"id":"CVE-2023-37378-ebfbcc44","signature_type":"Function","signature_version":"v1","source":"https://github.com/nsis-dev/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967"},{"deprecated":false,"digest":{"line_hashes":["60543037167232676067549862839017220593","76046088486453568946336336722720563975","275640915613554648152563760476393195678","172676567540280631963649980876456781514","4289035430264387161276554649485414837","291520104958682271676366889532797284590","162135200464859797397507481780335903973","85226076787956403500313454633934366283","233432201394001661051155709591834078895","313874196478770005358584940841620236403","160653053246226962671467081784280584519","221222718719831732657784172275636846018","247806732783732742629530897144882437358","200250014606682383813935174808415964487","150533182142403155017917992531036182334","139963057636399141210237298990742456137","44501027052060518232755270189537024105","113071475526878485971776268039702823427","122864058405360369512309200936464639512","223179574942757062959591364325928774728","98032065988930303444066284287075984383","164950581094023096263630925339827005326","279948318976633098179475554496007811596","67209035163701503300638619594651603987","229007476203784657544402366885108667631","179549671273348806821548131167239526405","303993718806375606604641388294266553298","201473867717459035062995724688689687325","119394310189101375440086207481608574445","33111018883604039292587137378230719654","173825978292864369792481519406267853609","237570166645348850479640077180332630435","272013930704657037434137343990911428054","75493550936600032105303780860033650504","225068793697838432106127259804466543092","260275924475928678392964062323325008452","65533719156362105250301084449697781109","336838171282105654712498653543023844572","163278874613214724575856359767770856499","111725296115406526554234627055903835505","69153807055451316838089752882424565985","117170084492708316349714162838958332660"],"threshold":0.9},"id":"CVE-2023-37378-f96d0ac5","signature_type":"Line","signature_version":"v1","source":"https://github.com/nsis-dev/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967","target":{"file":"Source/exehead/Main.c"}}]}}],"schema_version":"1.9.0"}