Vulnerability Description
Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configuration data by reading a file.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mumble | Mumble | <= 1.2.3 |
Related Weaknesses (CWE)
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659039
- http://bugs.gentoo.org/show_bug.cgi?id=403939
- http://secunia.com/advisories/47951
- http://www.debian.org/security/2012/dsa-2411
- http://www.openwall.com/lists/oss-security/2012/02/15/1
- http://www.openwall.com/lists/oss-security/2012/02/15/2
- http://www.securityfocus.com/bid/52024
- https://bugs.launchpad.net/ubuntu/+source/mumble/+bug/783405
- https://bugzilla.redhat.com/show_bug.cgi?id=791000
- https://github.com/mumble-voip/mumble/commit/5632c35d6759f5e13a7dfe78e4ee6403ff6
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659039
- http://bugs.gentoo.org/show_bug.cgi?id=403939
- http://secunia.com/advisories/47951
- http://www.debian.org/security/2012/dsa-2411
- http://www.openwall.com/lists/oss-security/2012/02/15/1
FAQ
What is CVE-2012-0863?
CVE-2012-0863 is a vulnerability with a CVSS score of 2.1 (LOW). Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configu...
How severe is CVE-2012-0863?
CVE-2012-0863 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0863?
Check the references section above for vendor advisories and patch information. Affected products include: Mumble Mumble.