Input validation error in mumble - CVE-2021-27229

 

Input validation error in mumble - CVE-2021-27229

Published: February 22, 2021


Vulnerability identifier: #VU50817
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-27229
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
mumble
Software vendor:
mumble-voip

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input when processing URL schemes. A remote attacker can create a specially crafted web page, trick the victim to open the web page, click on the "Open Webpage text" and execute arbitrary code on the system.


Remediation

Install updates from vendor's website.

External links