Mumble CVE-2014-0045 Heap Based Buffer Overflow Vulnerability
BID:65374
Info
Mumble CVE-2014-0045 Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 65374 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-0045 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2014 12:00AM |
| Updated: | Apr 13 2015 10:09PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Mumble Mumble 1.2.4 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Mumble Mumble 1.2.5 |
Discussion
Mumble CVE-2014-0045 Heap Based Buffer Overflow Vulnerability
Mumble is prone to a heap-based buffer overflow vulnerability.
Successful exploits will allow attackers to crash an affected application, resulting in a denial-of-service condition. Due to the nature of these issues, code execution may be possible; however, it has not been confirmed.
Mumble 1.2.4 is vulnerable; other versions may also be affected.
Mumble is prone to a heap-based buffer overflow vulnerability.
Successful exploits will allow attackers to crash an affected application, resulting in a denial-of-service condition. Due to the nature of these issues, code execution may be possible; however, it has not been confirmed.
Mumble 1.2.4 is vulnerable; other versions may also be affected.
Exploit / POC
Mumble CVE-2014-0045 Heap Based Buffer Overflow Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Mumble CVE-2014-0045 Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Mumble CVE-2014-0045 Heap Based Buffer Overflow Vulnerability
References:
References:
- Mumble Homepage (Mumble)
- Mumble Security Advisory 2014-001 (Mumble)
- Mumble Security Advisory 2014-002 (Mumble)