First published: Mon Apr 20 2020(Updated: )
InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Installbuilder | <19.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3946 has been assessed as a high severity vulnerability due to its potential to cause denial-of-service through the Billion laughs attack.
To mitigate CVE-2020-3946, upgrade your VMware InstallBuilder to version 19.11 or later.
The Billion laughs attack is a form of denial-of-service that exploits the XML parser's ability to handle nested entities, leading to resource exhaustion.
VMware InstallBuilder versions earlier than 19.11 are vulnerable to CVE-2020-3946.
The impact of CVE-2020-3946 includes system unavailability and potential disruption of services due to a denial-of-service attack.