CVE-2018-20743

NONE EPSS 88.1%
Published Jan 25, 20197y ago · Modified Jun 17, 20262w ago
Find Similar
Published Jan 25, 2019 7y ago
Last Modified Jun 17, 2026 2w ago

Description

murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.

Threat Intelligence

EPSS Exploit Probability
88.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-20 Improper Input Validation Validation

Affected Products 3

VendorProductVersionRange
mumblemumble* ≤1.2.19
debiandebian_linux8.0any
debiandebian_linux9.0any

References 9

  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00045.html
  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00023.html
  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00058.html
  • bugs.debian.org https://bugs.debian.org/919249
    Issue TrackingMailing ListThird Party Advisory
  • github.com https://github.com/mumble-voip/mumble/issues/3505
    PatchThird Party Advisory
  • github.com https://github.com/mumble-voip/mumble/pull/3510
    PatchThird Party Advisory
  • github.com https://github.com/mumble-voip/mumble/pull/3512
    PatchThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2019/02/msg00006.html
    Third Party Advisory
  • debian.org https://www.debian.org/security/2019/dsa-4402
    Third Party Advisory

Remediation

  • github.com https://github.com/mumble-voip/mumble/issues/3505
    PatchThird Party Advisory
  • github.com https://github.com/mumble-voip/mumble/pull/3510
    PatchThird Party Advisory
  • github.com https://github.com/mumble-voip/mumble/pull/3512
    PatchThird Party Advisory