// For flags

CVE-2014-0044

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The opus_packet_get_samples_per_frame function in client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots allows remote attackers to cause a denial of service (crash) via a crafted length prefix value, which triggers a NULL pointer dereference or a heap-based buffer over-read (aka "out-of-bounds array access").

La función opus_packet_get_samples_per_frame en client en Mumble 1.2.4 y las instantáneas pre-lanzamiento de 1.2.3 permite a atacantes remotos causar una denegación de servicio (caída) a través de un valor de una longitud de prefijo manipulado, lo que provoca una referencia a puntero nulo o una sobre-lectura de buffer basada en memoria dinámica (también conocido como "acceso a array fuera de rango").

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-03 CVE Reserved
  • 2014-02-05 CVE Published
  • 2023-04-24 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Light Speed Gaming
Search vendor "Light Speed Gaming"
Mumble
Search vendor "Light Speed Gaming" for product "Mumble"
1.2.3
Search vendor "Light Speed Gaming" for product "Mumble" and version "1.2.3"
rc1
Affected
Light Speed Gaming
Search vendor "Light Speed Gaming"
Mumble
Search vendor "Light Speed Gaming" for product "Mumble"
1.2.3
Search vendor "Light Speed Gaming" for product "Mumble" and version "1.2.3"
rc2
Affected
Light Speed Gaming
Search vendor "Light Speed Gaming"
Mumble
Search vendor "Light Speed Gaming" for product "Mumble"
1.2.3
Search vendor "Light Speed Gaming" for product "Mumble" and version "1.2.3"
rc3
Affected
Light Speed Gaming
Search vendor "Light Speed Gaming"
Mumble
Search vendor "Light Speed Gaming" for product "Mumble"
1.2.4
Search vendor "Light Speed Gaming" for product "Mumble" and version "1.2.4"
-
Affected