Information disclosure in InstallShield - CVE-2007-6744

 

Information disclosure in InstallShield - CVE-2007-6744

Published: January 19, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44374
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2007-6744
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Macrovision Corporation
Affected software:
InstallShield

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between InstallShield and Signcode.exe.


How to mitigate CVE-2007-6744

Install update from vendor's website.

Sources