CVE-2014-3756
Publication date 16 November 2014
Last updated 24 July 2024
Ubuntu priority
The client in Mumble 1.2.x before 1.2.6 allows remote attackers to force the loading of an external file and cause a denial of service (hang and resource consumption) via a crafted string that is treated as rich-text by a Qt widget, as demonstrated by the (1) user or (2) channel name in a Qt dialog, (3) subject common name or (4) email address to the Certificate Wizard, or (5) server name in a tooltip.
Status
Package | Ubuntu Release | Status |
---|---|---|
mumble | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1.2.4-0.2ubuntu1.1
|
|
Patch details
Package | Patch details |
---|---|
mumble |