Executable installers are vulnerable^WEVIL (case 11): Nmap <7.01 and Nmap-WinPcap <4.13

Posted by Stefan Kanthak on Dec 16

Hi @ll,

the executable installers of Nmap-7.00 and prior versions (see
<https://nmap.org/download.html>) as well as WinPcap-Nmap-4.12 and
prior versions (included in nmap-7.00-win32.zip and prior versions)
are built with the vulnerable Nullsoft Scriptable Install System
(NSIS) (see <http://seclists.org/fulldisclosure/2015/Dec/32> for
details).

These executable installers are vulnerable and allow arbitrary
(remote) code execution and…

Leave a Reply