IBM Security Bulletin: Vulnerability in InstallShield/InstallAnywhere affects IBM Informix CSDK and Server installation on Windows(CVE-2016-2542, CVE-2016-4560)
InstallShield/installAnywhere generates installation executables which are vulnerable to a DLL-planting affecting the installation of IBM Informix CSDK and Dynamic Server on Windows.
CVE(s): CVE-2016-2542, CVE-2016-4560
Affected product(s) and affected version(s):
IBM Informix CSDK 3.50, 3.70, 4.10 for Windows
IBM Informix Dynamic Server 11.50, 11.70, 12.10 for Windows
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1UilDIV
X-Force Database: http://ift.tt/1rhWtyP
X-Force Database: http://ift.tt/1Vw3dW4
from IBM Product Security Incident Response Team http://ift.tt/1TXAbKm