SB2019012520 - Input validation error in wiki.mumble.info mumble
Published: January 25, 2019 Updated: August 3, 2020
Security Bulletin ID
SB2019012520
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2018-20743)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.
Remediation
Install update from vendor's website.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00058.html
- https://bugs.debian.org/919249
- https://github.com/mumble-voip/mumble/issues/3505
- https://github.com/mumble-voip/mumble/pull/3510
- https://github.com/mumble-voip/mumble/pull/3512
- https://lists.debian.org/debian-lts-announce/2019/02/msg00006.html
- https://www.debian.org/security/2019/dsa-4402