CVE-2010-2490: Input Validation
Mumble: murmur-server has DoS due to malformed client query
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2010-2490?
CVE-2010-2490 is a vulnerability in Mumble's murmur-server that allows for a denial-of-service (DoS) attack due to a malformed client query.
What software is affected by CVE-2010-2490?
The Mumble package versions 1.3.0~git20190125.440b173+dfsg-2+deb10u1, 1.3.4-1, and 1.3.4-4, as well as the qt4-x11 package version 4:4.8.7+dfsg-18+deb10u1 on Debian Linux versions 8.0, 9.0, and 10.0 are affected by CVE-2010-2490.
What is the severity of CVE-2010-2490?
CVE-2010-2490 has a severity score of 6.5, indicating a medium severity.
How can I fix CVE-2010-2490?
To fix CVE-2010-2490, update the affected Mumble package versions to 1.3.4-5 or later, and update the affected qt4-x11 package version to 4:4.8.7+dfsg-18+deb10u2 or later on Debian Linux.
Where can I find more information about CVE-2010-2490?
You can find more information about CVE-2010-2490 on the following references: [https://security-tracker.debian.org/tracker/CVE-2010-2490](https://security-tracker.debian.org/tracker/CVE-2010-2490), [https://access.redhat.com/security/cve/cve-2010-2490](https://access.redhat.com/security/cve/cve-2010-2490), [https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2490](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2490).