MGASA-2019-0145 - Updated mumble packages fix security vulnerability

Publication date: 10 Apr 2019
URL: https://advisories.mageia.org/MGASA-2019-0145.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-20743

It was discovered that insufficient restrictions in the connection
handling of Mumble, a low latency encrypted VoIP client, could result in
denial of service (CVE-2018-20743).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24479
- https://security-tracker.debian.org/tracker/CVE-2018-20743
- https://www.debian.org/security/2019/dsa-4402
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20743

SRPMS:
- 6/core/mumble-1.2.19-1.1.mga6

Mageia 2019-0145: mumble security update

It was discovered that insufficient restrictions in the connection handling of Mumble, a low latency encrypted VoIP client, could result in denial of service (CVE-2018-20743)

Summary

It was discovered that insufficient restrictions in the connection handling of Mumble, a low latency encrypted VoIP client, could result in denial of service (CVE-2018-20743).

References

- https://bugs.mageia.org/show_bug.cgi?id=24479

- https://security-tracker.debian.org/tracker/CVE-2018-20743

- https://www.debian.org/security/2019/dsa-4402

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20743

Resolution

MGASA-2019-0145 - Updated mumble packages fix security vulnerability

SRPMS

- 6/core/mumble-1.2.19-1.1.mga6

Severity
Publication date: 10 Apr 2019
URL: https://advisories.mageia.org/MGASA-2019-0145.html
Type: security
CVE: CVE-2018-20743

Related News