First published: Fri Jan 25 2019(Updated: )
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mumble | 1.3.0~git20190125.440b173+dfsg-2+deb10u1 1.3.4-1 1.3.4-4 | |
Mumble Mumble | <=1.2.19 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-20743.
The title of this vulnerability is 'murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests'.
The severity level of CVE-2018-20743 is high, with a severity value of 7.5.
CVE-2018-20743 affects Mumble versions 1.2.19 before 2018-08-31.
Remote attackers can exploit CVE-2018-20743 by causing a denial of service (daemon hang or crash) through a message flood.