Input validation error in mumble - CVE-2021-27229
Published: February 22, 2021
mumble
mumble-voip
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input when processing URL schemes. A remote attacker can create a specially crafted web page, trick the victim to open the web page, click on the "Open Webpage text" and execute arbitrary code on the system.