Hi, On Tuesday 01 December 2015 19:44:36 you wrote: > I would propose to wait for the review and the fix going in upstream. > Thereafter the fix could be back ported to the NSIS version distributed > by Debian.
I agree. NSIS upstream reacted quickly and while it is of no concern to us (at gpg4win) I guess for Debian it could be problematic to ship a Version that is not compatible with all the Windows Versions NSIS is compatible with (versions before Windows XP). We've published the patched packages we used for our last Installer package under http://apt.intevation.de for both wheezy and jessie. ( deb http://apt.intevation.de jessie nsis ) Btw. we've also published a security advisory about this problem in relation to Gpg4win. https://gpg4win.de/news-20151125.html Thanks for your work on the Debian NSIS package. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner