CVE-2018-20743: Input Validation
Published Jan 25, 2019
·Updated
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.
Affected Software
4 affected componentsFixes available
debian/mumble
1.3.0~git20190125.440b173+dfsg-2+deb10u11.3.4-11.3.4-4
Mumble Mumble<=1.2.19
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 25, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-20743.
2
What is the title of this vulnerability?
The title of this vulnerability is 'murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests'.
3
What is the severity level of CVE-2018-20743?
The severity level of CVE-2018-20743 is high, with a severity value of 7.5.
4
How does CVE-2018-20743 affect Mumble?
CVE-2018-20743 affects Mumble versions 1.2.19 before 2018-08-31.
5
How can remote attackers exploit CVE-2018-20743?
Remote attackers can exploit CVE-2018-20743 by causing a denial of service (daemon hang or crash) through a message flood.