Back to Database
Status published
High
CVE-2021-27229
Mumble before 1.3.4 allows remote code execution if a victim...
Vulnerability Description
Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-27229
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/mumble-voip/mumble/compare/1.3.3...1.3.4
- https://github.com/mumble-voip/mumble/pull/4733
- https://github.com/mumble-voip/mumble/commit/e59ee87abe249f345908c7d568f6879d16bfd648
- https://lists.debian.org/debian-lts-announce/2021/02/msg00022.html
- https://security.gentoo.org/glsa/202105-13
More from mumble
View All →CVE-2020-13962
Qt 5.12.2 through 5.14.2, as used in unofficial builds of...
High
7.5
CVE-2018-20743
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent...
High
7.5
CVE-2014-3756
The client in Mumble 1.2.x before 1.2.6 allows remote attackers...
Medium
5
CVE-2014-3755
The QSvg module in Qt, as used in the Mumble...
Medium
5
CVE-2012-0863
Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files...
Low
2.1
Affected Vendor
mumble
View all reports →Affected Software
mumble, debian linux
Vulnerable Versions:
0, 9.0
Timeline
Official Publish:
February 16th, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.