ArchLinux: 202102-32: mumble: arbitrary code execution
Summary
Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
Resolution
Upgrade to 1.3.4-1.
# pacman -Syu "mumble>=1.3.4-1"
The problem has been fixed upstream in version 1.3.4.
References
https://github.com/mumble-voip/mumble/pull/4733 https://github.com/mumble-voip/mumble/commit/e59ee87abe249f345908c7d568f6879d16bfd648 https://security.archlinux.org/CVE-2021-27229
Workaround
None.