CVE-2021-27229
published 2021-02-16CVE-2021-27229: Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.20%
86.9th percentile
Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mumble | < mumble 1.3.4-1 (bookworm) | mumble 1.3.4-1 (bookworm) |
| mumble | mumble | < 1.3.4 | 1.3.4 |
| mumble | mumble | >= 0 < 1.3.4-1 | 1.3.4-1 |
| mumble | mumble | >= 0 < 1.3.4-1 | 1.3.4-1 |
| mumble | mumble | >= 0 < 1.3.4-1 | 1.3.4-1 |
| mumble | mumble | >= 0 < 1.3.4-1 | 1.3.4-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-58v9-jf45-v492: Mumble before 1
ghsa_unreviewed·2022-05-24
CVE-2021-27229 [HIGH] CWE-59 GHSA-58v9-jf45-v492: Mumble before 1
Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
OSV
CVE-2021-27229: Mumble before 1
osv·2021-02-16·CVSS 8.8
CVE-2021-27229 [HIGH] CVE-2021-27229: Mumble before 1
Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
Ubuntu
Mumble vulnerability
vendor_ubuntu·2021-12-16
CVE-2021-27229 Mumble vulnerability
Title: Mumble vulnerability
Summary: A security issue was fixed in Mumble.
It was discovered that the Mumble client supported websites for public servers
with arbitrary URL schemes. If a user were tricked into visiting a malicious
website from the public server list, a remote attacker could possibly execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-27229: mumble - Mumble before 1.3.4 allows remote code execution if a victim navigates to a craf...
vendor_debian·2021·CVSS 8.8
CVE-2021-27229 [HIGH] CVE-2021-27229: mumble - Mumble before 1.3.4 allows remote code execution if a victim navigates to a craf...
Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
Scope: local
bookworm: resolved (fixed in 1.3.4-1)
bullseye: resolved (fixed in 1.3.4-1)
forky: resolved (fixed in 1.3.4-1)
sid: resolved (fixed in 1.3.4-1)
trixie: resolved (fixed in 1.3.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/mumble-voip/mumble/commit/e59ee87abe249f345908c7d568f6879d16bfd648https://github.com/mumble-voip/mumble/compare/1.3.3...1.3.4https://github.com/mumble-voip/mumble/pull/4733https://lists.debian.org/debian-lts-announce/2021/02/msg00022.htmlhttps://security.gentoo.org/glsa/202105-13https://github.com/mumble-voip/mumble/commit/e59ee87abe249f345908c7d568f6879d16bfd648https://github.com/mumble-voip/mumble/compare/1.3.3...1.3.4https://github.com/mumble-voip/mumble/pull/4733https://lists.debian.org/debian-lts-announce/2021/02/msg00022.htmlhttps://security.gentoo.org/glsa/202105-13
2021-02-16
Published