Bug 1182123 - (CVE-2021-27229) VUL-0: CVE-2021-27229 : mumble: non-http/https URL schemes in website field
(CVE-2021-27229)
VUL-0: CVE-2021-27229 : mumble: non-http/https URL schemes in website field
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.2
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
E-mail List
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-02-11 13:08 UTC by Andreas Stieger
Modified: 2021-02-19 20:26 UTC (History)
4 users (show)

See Also:
Found By: Community User
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2021-02-11 13:08:56 UTC
Fixed in Mumble 1.3.4:

> Fixed: Security vulnerability caused by allowing non http/https URL schemes in
> public server 

From commit:

Our public server list registration script doesn't have an URL scheme whitelist for the website field. Turns out a malicious server can register itself with a dangerous URL in an attempt to attack a user's machine. User interaction is required, as the URL has to be opened by right-clicking on the server entry and clicking on Open Webpage.
[.fix is a ..] client-side whitelist, which only allows http and https schemes.

References:
https://github.com/mumble-voip/mumble/pull/4733
https://github.com/mumble-voip/mumble/commit/817d2c1a03cdeb0d951b0460c5c03c504fdeed40
https://github.com/mumble-voip/mumble/pull/4739
https://github.com/mumble-voip/mumble/commit/6b54dbca8589140d5ae2ed9b0eb89590fa18d6e6
Comment 1 Alexandros Toptsoglou 2021-02-11 13:30:37 UTC
Factory needs upgrade and I think it is safe to bump to 1.3.4 in Leap 15.2 too
Comment 2 Andreas Stieger 2021-02-11 15:37:32 UTC
https://build.opensuse.org/request/show/871215
Comment 3 OBSbugzilla Bot 2021-02-12 10:20:12 UTC
This is an autogenerated message for OBS integration:
This bug (1182123) was mentioned in
https://build.opensuse.org/request/show/871382 15.2 / mumble
Comment 4 OBSbugzilla Bot 2021-02-12 18:20:11 UTC
This is an autogenerated message for OBS integration:
This bug (1182123) was mentioned in
https://build.opensuse.org/request/show/871515 15.2 / mumble
Comment 5 Swamp Workflow Management 2021-02-16 14:15:56 UTC
openSUSE-SU-2021:0300-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 1180068,1182123
CVE References: 
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    mumble-1.3.4-lp152.2.6.1
Comment 6 Alexandros Toptsoglou 2021-02-16 14:19:18 UTC
Done
Comment 7 OBSbugzilla Bot 2021-02-16 15:10:06 UTC
This is an autogenerated message for OBS integration:
This bug (1182123) was mentioned in
https://build.opensuse.org/request/show/872855 Backports:SLE-15-SP3 / mumble
Comment 8 Swamp Workflow Management 2021-02-19 20:26:06 UTC
openSUSE-SU-2021:0312-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 1180068,1182123
CVE References: 
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    mumble-1.3.4-bp152.2.6.1