PT-2021-27328 · Mumble · Mumble
Published
2021-02-19
·
Updated
2021-02-19
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
mumble versions prior to 1.3.4
Description:
The issue is caused by allowing non http/https URL schemes in the public server list. This has been fixed in the update to version 1.3.4. Other fixes include handling of invalid packet sizes, race-condition leading to loss of shortcuts, and sizing issues in the ACL-Editor.
Recommendations:
For versions prior to 1.3.4, update to version 1.3.4 to resolve the issue. As a temporary workaround, consider restricting the use of non http/https URL schemes in the public server list until the update is applied.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mumble