We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2015-0941



Assignercertcc
Reserved2015-01-10
Published2015-03-22
Updated2024-08-06

Description

The Inetc plugin for Nullsoft Scriptable Install System (NSIS), as used in CERT/CC Failure Observation Engine (FOE) and other products, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and possibly execute arbitrary code by sending a crafted certificate in a download session for Windows executable files.

References

http://www.kb.cert.org/vuls/id/894897 (VU#894897) third-party-advisory

cve.org CVE-2015-0941

nvd.nist.gov CVE-2015-0941

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2015-0941
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.