CVE-2014-1916
Summary
| CVE | CVE-2014-1916 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-08 00:55:06 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The (1) opus_packet_get_nb_frames and (2) opus_packet_get_samples_per_frame functions in the client in MumbleKit before commit fd190328a9b24d37382b269a5674b0c0c7a7e36d and Mumble for iOS 1.1 through 1.2.2 do not properly check the return value of the copyDataBlock method, which allow remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted length prefix value in an Opus voice packet. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS: 0.004740000 probability, percentile 0.647800000 (date 2026-05-04)
Problem Types: CWE-399 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Light Speed Gaming | Mumble | 1.1 | All | All | All |
| Application | Light Speed Gaming | Mumble | 1.1 | rc1 | All | All |
| Application | Light Speed Gaming | Mumble | 1.1.1 | All | All | All |
| Application | Light Speed Gaming | Mumble | 1.2 | All | All | All |
| Application | Light Speed Gaming | Mumble | 1.2.1 | All | All | All |
| Application | Light Speed Gaming | Mumble | 1.2.2 | All | All | All |
| Application | Light Speed Gaming | Mumblekit | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/102957 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| mumble.info/security/Mumble-SA-2014-003.txt | af854a3a-2127-422b-91ae-364da2661108 | mumble.info | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.