PT-2014-1785 · Mumble · Mumble

Publicado

2014-02-08

·

Atualizado

2024-06-15

·

CVE-2014-0044

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mumble versions 1.2.3 through 1.2.4
Description The issue allows remote attackers to cause a denial of service, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This is achieved through the opus packet get samples per frame function in the client, where a crafted length prefix value can trigger a NULL pointer dereference or a heap-based buffer over-read, also known as "out-of-bounds array access".
Recommendations For Mumble version 1.2.3, consider upgrading to a version later than 1.2.4 to resolve the issue. For Mumble version 1.2.4, consider upgrading to a version later than 1.2.4 to resolve the issue. As a temporary workaround, consider restricting access to the opus packet get samples per frame function until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04025
CVE-2014-0044
DSA-2854-1
OPENSUSE-SU-2024:10080-1

Produtos afetados

Mumble