{"id":"MGASA-2014-0245","summary":"Updated mumble packages fix two security vulnervabilitites","details":"Updated mumble packages fix security vulnerabilities:\n\nIn Mumble before 1.2.6, the Mumble client is vulnerable to a Denial of\nService attack when rendering crafted SVG files that contain references to\nfiles on the local computer, due to an issue in Qt's SVG renderer module.\nThis issue can be triggered remotely by an entity participating in a Mumble\nvoice chat, using text messages, channel comments, user comments and user\ntextures/avatars (CVE-2014-3755).\n\nIn Mumble before 1.2.6, The Mumble client did not properly HTML-escape some\nexternal strings before using them in a rich-text (HTML) context. In some\nsituations, this could be abused to perform a Denial of Service attack on a\nMumble client by causing it to load external files via the HTML\n(CVE-2014-3756).\n","modified":"2026-04-16T06:25:53.361899142Z","published":"2014-05-30T07:47:09Z","upstream":["CVE-2014-3755","CVE-2014-3756"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0245.html"},{"type":"WEB","url":"http://mumble.info/security/Mumble-SA-2014-005.txt"},{"type":"WEB","url":"http://mumble.info/security/Mumble-SA-2014-006.txt"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/05/15/4"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13382"}],"affected":[{"package":{"name":"mumble","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/mumble?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.3-10.1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0245.json"}},{"package":{"name":"mumble","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/mumble?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.3-14.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0245.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}