IBM Security Bulletin: Vulnerability in InstallShield/InstallAnywhere affects IBM Informix CSDK and Server installation on Windows(CVE-2016-2542, CVE-2016-4560)

InstallShield/installAnywhere generates installation executables which are vulnerable to a DLL-planting affecting the installation of IBM Informix CSDK and Dynamic Server on Windows.

CVE(s): CVE-2016-2542, CVE-2016-4560

Affected product(s) and affected version(s):

IBM Informix CSDK 3.50, 3.70, 4.10 for Windows

IBM Informix Dynamic Server 11.50, 11.70, 12.10 for Windows

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1UilDIV
X-Force Database: http://ift.tt/1rhWtyP
X-Force Database: http://ift.tt/1Vw3dW4



from IBM Product Security Incident Response Team http://ift.tt/1TXAbKm