CVE-2020-3946: High severity vmware installbuilder vulnerability
InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3946?
CVE-2020-3946 has been assessed as a high severity vulnerability due to its potential to cause denial-of-service through the Billion laughs attack.
How do I fix CVE-2020-3946?
To mitigate CVE-2020-3946, upgrade your VMware InstallBuilder to version 19.11 or later.
What is the Billion laughs attack related to CVE-2020-3946?
The Billion laughs attack is a form of denial-of-service that exploits the XML parser's ability to handle nested entities, leading to resource exhaustion.
Which versions of VMware InstallBuilder are affected by CVE-2020-3946?
VMware InstallBuilder versions earlier than 19.11 are vulnerable to CVE-2020-3946.
What is the potential impact of CVE-2020-3946?
The impact of CVE-2020-3946 includes system unavailability and potential disruption of services due to a denial-of-service attack.