First published: Mon Jun 08 2020(Updated: )
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/QT | <5.12.9 | 5.12.9 |
redhat/QT | <5.14.3 | 5.14.3 |
redhat/QT | <5.15.0 | 5.15.0 |
Mumble Mumble | =1.3.0 | |
Qt Qt | >=5.12.2<5.12.9 | |
Qt Qt | >=5.13.0<=5.13.2 | |
Qt Qt | >=5.14.0<=5.14.2 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
openSUSE Leap | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Qt versions 5.12.2 through 5.14.2 are affected by CVE-2020-13962.
Yes, unofficial builds of Mumble version 1.3.0 are affected by CVE-2020-13962.
The severity of CVE-2020-13962 is high, with a CVSS score of 7.5.
To fix CVE-2020-13962 in Qt, update to version 5.12.9, 5.14.3, or 5.15.0.
Yes, you can find more information about CVE-2020-13962 in the following references: [link1](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00004.html), [link2](https://bugreports.qt.io/browse/QTBUG-83450), [link3](https://github.com/mumble-voip/mumble/issues/3679).