Bugzilla – Bug 1182123
VUL-0: CVE-2021-27229 : mumble: non-http/https URL schemes in website field
Last modified: 2021-02-19 20:26:06 UTC
Fixed in Mumble 1.3.4: > Fixed: Security vulnerability caused by allowing non http/https URL schemes in > public server From commit: Our public server list registration script doesn't have an URL scheme whitelist for the website field. Turns out a malicious server can register itself with a dangerous URL in an attempt to attack a user's machine. User interaction is required, as the URL has to be opened by right-clicking on the server entry and clicking on Open Webpage. [.fix is a ..] client-side whitelist, which only allows http and https schemes. References: https://github.com/mumble-voip/mumble/pull/4733 https://github.com/mumble-voip/mumble/commit/817d2c1a03cdeb0d951b0460c5c03c504fdeed40 https://github.com/mumble-voip/mumble/pull/4739 https://github.com/mumble-voip/mumble/commit/6b54dbca8589140d5ae2ed9b0eb89590fa18d6e6
Factory needs upgrade and I think it is safe to bump to 1.3.4 in Leap 15.2 too
https://build.opensuse.org/request/show/871215
This is an autogenerated message for OBS integration: This bug (1182123) was mentioned in https://build.opensuse.org/request/show/871382 15.2 / mumble
This is an autogenerated message for OBS integration: This bug (1182123) was mentioned in https://build.opensuse.org/request/show/871515 15.2 / mumble
openSUSE-SU-2021:0300-1: An update that contains security fixes can now be installed. Category: security (moderate) Bug References: 1180068,1182123 CVE References: JIRA References: Sources used: openSUSE Leap 15.2 (src): mumble-1.3.4-lp152.2.6.1
Done
This is an autogenerated message for OBS integration: This bug (1182123) was mentioned in https://build.opensuse.org/request/show/872855 Backports:SLE-15-SP3 / mumble
openSUSE-SU-2021:0312-1: An update that contains security fixes can now be installed. Category: security (moderate) Bug References: 1180068,1182123 CVE References: JIRA References: Sources used: openSUSE Backports SLE-15-SP2 (src): mumble-1.3.4-bp152.2.6.1