IBM Security Bulletin: IBM Notes InstallShield vulnerable to DLL planting (CVE-2016-2542)
IBM Notes uses InstallShield which generates install executables that are vulnerable to a DLL-planting vulnerability.
CVE(s): CVE-2016-2542
Affected product(s) and affected version(s):
This vulnerability affects installers of following versions of IBM Notes
– IBM Notes 9.0.1
– IBM Notes 9.0
– IBM Notes 8.5.3
– IBM Notes 8.5.2
– IBM Notes 8.5.1
– IBM Notes 8.5
This vulnerability does not affect Fix Pack or Interim Fix installers.
This vulnerability does not affect installed versions of IBM Notes.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1syxxE8
X-Force Database: http://ift.tt/1rhWtyP
from IBM Product Security Incident Response Team http://ift.tt/25RwugP