PT-2021-27328 · Mumble · Mumble

Published

2021-02-19

·

Updated

2021-02-19

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: mumble versions prior to 1.3.4
Description: The issue is caused by allowing non http/https URL schemes in the public server list. This has been fixed in the update to version 1.3.4. Other fixes include handling of invalid packet sizes, race-condition leading to loss of shortcuts, and sizing issues in the ACL-Editor.
Recommendations: For versions prior to 1.3.4, update to version 1.3.4 to resolve the issue. As a temporary workaround, consider restricting the use of non http/https URL schemes in the public server list until the update is applied.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

OPENSUSE-SU-2021:0312-1

Affected Products

Mumble