Bugzilla – Bug 877971
VUL-0: CVE-2014-3756: mumble: Remote DoS via unescaped HTML in external strings
Last modified: 2014-05-23 08:21:17 UTC
Via OSS:2014/Q2/317 The Mumble client did not properly HTML-escape some external strings before using them in a rich-text (HTML) context (CVE-2014-3756). All 1.2.x versions of Mumble are affected. References: http://seclists.org/oss-sec/2014/q2/317 http://mumble.info/security/Mumble-SA-2014-006.txt
This is an autogenerated message for OBS integration: This bug (877971) was mentioned in https://build.opensuse.org/request/show/234170 Factory / mumble https://build.opensuse.org/request/show/234171 12.3 / mumble https://build.opensuse.org/request/show/234172 13.1 / mumble
bugbot adjusting priority
openSUSE-SU-2014:0706-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 877969,877971 CVE References: CVE-2014-3755,CVE-2014-3756 Sources used: openSUSE 13.1 (src): mumble-1.2.6-2.12.2 openSUSE 12.3 (src): mumble-1.2.6-21.8.1
fixed all affected openSUSE versions. Thank you.