Vulnerability Description
InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Installbuilder | < 19.11.0 |
Related Weaknesses (CWE)
References
- https://blog.installbuilder.com/2019/12/configure-autoupdate-project-settings.htVendor Advisory
- https://blog.installbuilder.com/2019/12/configure-autoupdate-project-settings.htVendor Advisory
FAQ
What is CVE-2020-3946?
CVE-2020-3946 is a vulnerability with a CVSS score of 7.5 (HIGH). InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).
How severe is CVE-2020-3946?
CVE-2020-3946 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-3946?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Installbuilder.