Debian DSA-2854-1 : mumble - several vulnerabilities

high Nessus Plugin ID 72354

Synopsis

The remote Debian host is missing a security-related update.

Description

Several issues have been discovered in mumble, a low latency VoIP client. The Common Vulnerabilities and Exposures project identifies the following issues :

- CVE-2014-0044 It was discovered that a malformed Opus voice packet sent to a Mumble client could trigger a NULL pointer dereference or an out-of-bounds array access. A malicious remote attacker could exploit this flaw to mount a denial of service attack against a mumble client by causing the application to crash.

- CVE-2014-0045 It was discovered that a malformed Opus voice packet sent to a Mumble client could trigger a heap-based buffer overflow. A malicious remote attacker could use this flaw to cause a client crash (denial of service) or potentially use it to execute arbitrary code.

The oldstable distribution (squeeze) is not affected by these problems.

Solution

Upgrade the mumble packages.

For the stable distribution (wheezy), these problems have been fixed in version 1.2.3-349-g315b5f5-2.2+deb7u1.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737739

https://security-tracker.debian.org/tracker/CVE-2014-0044

https://security-tracker.debian.org/tracker/CVE-2014-0045

https://packages.debian.org/source/wheezy/mumble

https://www.debian.org/security/2014/dsa-2854

Plugin Details

Severity: High

ID: 72354

File Name: debian_DSA-2854.nasl

Version: 1.9

Type: local

Agent: unix

Published: 2/6/2014

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:mumble, cpe:/o:debian:debian_linux:7.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 2/5/2014

Reference Information

CVE: CVE-2014-0044, CVE-2014-0045

DSA: 2854