CVE-2018-20743
NONE EPSS 88.1%
Published Jan 25, 20197y ago · Modified Jun 17, 20262w ago
Published Jan 25, 2019 7y ago
Last Modified Jun 17, 2026 2w ago
Description
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.
Threat Intelligence
EPSS Exploit Probability
88.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-20 Improper Input Validation Validation
Affected Products 3
References 9
- lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00045.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00023.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00058.html
- bugs.debian.org https://bugs.debian.org/919249
- github.com https://github.com/mumble-voip/mumble/issues/3505
- github.com https://github.com/mumble-voip/mumble/pull/3510
- github.com https://github.com/mumble-voip/mumble/pull/3512
- lists.debian.org https://lists.debian.org/debian-lts-announce/2019/02/msg00006.html
- debian.org https://www.debian.org/security/2019/dsa-4402
Remediation
- github.com https://github.com/mumble-voip/mumble/issues/3505
- github.com https://github.com/mumble-voip/mumble/pull/3510
- github.com https://github.com/mumble-voip/mumble/pull/3512