Information disclosure in InstallShield - CVE-2007-6744

 

Information disclosure in InstallShield - CVE-2007-6744

Published: January 19, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44374
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2007-6744
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between InstallShield and Signcode.exe.


Affected software

InstallShield

How to mitigate CVE-2007-6744

Install update from vendor's website.


External References

Related Security Bulletins