CVE-2019-5530
Published Aug 29, 2019Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they contain a valid Authenticode signature.
Vendor archive
2 CVEs tagged to vendor bitrock — 0 Critical, 1 High, 0 Medium, 1 Low, 0 Unrated.
Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they contain a valid Authenticode signature.
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allow…