ALT-PU-2020-1881-1
Closed vulnerabilities
Published: 2018-08-27
BDU:2019-01544
Уязвимость серверного компонента Murmur программного средства для реализации IP-телефонии Mumble, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2019-01-25
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-20743
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.
Severity: HIGH (7.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2019:1794
- openSUSE-SU-2019:1794
- openSUSE-SU-2019:1876
- openSUSE-SU-2019:1876
- openSUSE-SU-2020:0137
- openSUSE-SU-2020:0137
- https://bugs.debian.org/919249
- https://bugs.debian.org/919249
- https://github.com/mumble-voip/mumble/issues/3505
- https://github.com/mumble-voip/mumble/issues/3505
- https://github.com/mumble-voip/mumble/pull/3510
- https://github.com/mumble-voip/mumble/pull/3510
- https://github.com/mumble-voip/mumble/pull/3512
- https://github.com/mumble-voip/mumble/pull/3512
- [debian-lts-announce] 20190206 [SECURITY] [DLA 1661-1] mumble security update
- [debian-lts-announce] 20190206 [SECURITY] [DLA 1661-1] mumble security update
- DSA-4402
- DSA-4402