Input validation error in mumble - CVE-2021-27229

 

Input validation error in mumble - CVE-2021-27229

Published: February 22, 2021


Vulnerability identifier: #VU50817
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27229
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input when processing URL schemes. A remote attacker can create a specially crafted web page, trick the victim to open the web page, click on the "Open Webpage text" and execute arbitrary code on the system.


Affected software

mumble
Arch Linux
Gentoo Linux
Ubuntu
mumble (Ubuntu package)

How to mitigate CVE-2021-27229

Install updates from vendor's website.

mumble - update to 1.3.4
mumble (Ubuntu package) - addressed in versions 1.2.19-1ubuntu1.1, 1.3.0+dfsg-1ubuntu0.1

External References

Related Security Bulletins