REDHAT-BUG-791000: SQL Injection
It was discovered that mumble created its database file (~/.local/share/data/Mumble/.mumble.sqlite) with insecure world-readable permissions. If the user had (non-default) permissions on their home directory, another local user could obtain password and configuration settings from the database file [1].
This has been corrected in upstream git [2] and is reported as affecting 1.2.3 and earlier.
[1] https://bugs.launchpad.net/ubuntu/+source/mumble/+bug/783405 [2] https://github.com/mumble-voip/mumble/commit/5632c35d6759f5e13a7dfe78e4ee6403ff6a8e3e
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-791000?
The severity of REDHAT-BUG-791000 is considered high due to the exposure of sensitive information.
How do I fix REDHAT-BUG-791000?
To fix REDHAT-BUG-791000, ensure that the database file permissions are set correctly to restrict access to only the owner.
Which versions of Mumble are affected by REDHAT-BUG-791000?
Mumble versions earlier than 1.2.4 are affected by REDHAT-BUG-791000.
What potential risks are associated with REDHAT-BUG-791000?
The main risk associated with REDHAT-BUG-791000 is that unauthorized users can access stored passwords and configuration settings.
Who is responsible for addressing REDHAT-BUG-791000?
The Mumble development team is responsible for addressing REDHAT-BUG-791000, and users should apply the software updates as released.