Vulnerability Description
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mumble | Mumble | 1.3.0 |
| Qt | Qt | >= 5.12.2, < 5.12.9 |
| Fedoraproject | Fedora | 31 |
| Opensuse | Leap | 15.2 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00004.htmlMailing ListThird Party Advisory
- https://bugreports.qt.io/browse/QTBUG-83450Issue TrackingVendor Advisory
- https://github.com/mumble-voip/mumble/issues/3679ExploitIssue TrackingPatch
- https://github.com/mumble-voip/mumble/pull/4032PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202007-18Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00004.htmlMailing ListThird Party Advisory
- https://bugreports.qt.io/browse/QTBUG-83450Issue TrackingVendor Advisory
- https://github.com/mumble-voip/mumble/issues/3679ExploitIssue TrackingPatch
- https://github.com/mumble-voip/mumble/pull/4032PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-13962?
CVE-2020-13962 is a vulnerability with a CVSS score of 7.5 (HIGH). Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors lea...
How severe is CVE-2020-13962?
CVE-2020-13962 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13962?
Check the references section above for vendor advisories and patch information. Affected products include: Mumble Mumble, Qt Qt, Fedoraproject Fedora, Opensuse Leap.