First published: Thu Oct 31 2019(Updated: )
Mumble: murmur-server has DoS due to malformed client query
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mumble Mumble | ||
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
debian/mumble | 1.3.4-1 1.3.4-4 1.5.517-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2490 is a vulnerability in Mumble's murmur-server that allows for a denial-of-service (DoS) attack due to a malformed client query.
The Mumble package versions 1.3.0~git20190125.440b173+dfsg-2+deb10u1, 1.3.4-1, and 1.3.4-4, as well as the qt4-x11 package version 4:4.8.7+dfsg-18+deb10u1 on Debian Linux versions 8.0, 9.0, and 10.0 are affected by CVE-2010-2490.
CVE-2010-2490 has a severity score of 6.5, indicating a medium severity.
To fix CVE-2010-2490, update the affected Mumble package versions to 1.3.4-5 or later, and update the affected qt4-x11 package version to 4:4.8.7+dfsg-18+deb10u2 or later on Debian Linux.
You can find more information about CVE-2010-2490 on the following references: [https://security-tracker.debian.org/tracker/CVE-2010-2490](https://security-tracker.debian.org/tracker/CVE-2010-2490), [https://access.redhat.com/security/cve/cve-2010-2490](https://access.redhat.com/security/cve/cve-2010-2490), [https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2490](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2490).