Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAAJZzgb-59N7fEaQ27-c8g1ri0dUjDQsf45SAv+GcRwK5MyWwQ@mail.gmail.com>
Date: Thu, 15 May 2014 02:35:53 +0200
From: Mikkel Krautz <mikkel@...utz.dk>
To: oss-security@...ts.openwall.com
Subject: Mumble 1.2.6: Mumble-SA-2014-005 and Mumble-SA-2014-006

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi oss-security,

The Mumble team has just released Mumble 1.2.6, which contains fixes
for the two following vulnerabilities:

  Mumble-SA-2014-005  [http://mumble.info/security/Mumble-SA-2014-005.txt]
    - SVG images with local file references could trigger client DoS

  Mumble-SA-2014-006  [http://mumble.info/security/Mumble-SA-2014-006.txt]
    - The Mumble client did not properly HTML-escape some external strings
       before using them in a rich-text (HTML) context.

Prepend '.sig' to the advisory URLs for detached PGP signatures
(signed with my key).

We would also kindly request that CVEs be assigned for the above issues.

Thanks,
Mikkel Krautz on behalf of the Mumble Team
PGP: 4096R/41BCDD10
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIcBAEBCgAGBQJTdAu8AAoJEIxe9eJBvN0Qw6EQAL7+tgY3fHEigHfSw7L0d4Gf
+f6r4uRuic/B8uoKho+7rI6hI4L/Ofr2zvGVnPRbZsrTeov3gK8fZ2rq65j1UtOx
qtRyj3gwSKlEZV4w4ak9naEN9nNx4uZRR5RKs5GNSVw/zArKGQ6WxzRznJWVU1MB
LWQk0thaQ2q0KOi39tivZVr5y0zQoDZU8Pq4XxeBtROpZJeLjgjEzUgMZZ89h/Hm
WwX8N/QygTJzTOs1f3z/8U0AUeM3YP1qB62DA3UUWz9PlHBrIdro5skaBrQWO2k2
kqjK6WnM1I0XTABiWVkjaUd9Q5HS60EDCW5Hg4i16IEFRI3UIH8v/9VSOth2GXG7
Ku1Db/ZXqffxb+0PcJyZGjtZ1yx2TtDBJBxpiRln8XZ2MeHM03COJMN6CSbp/VFy
oPtm4cypyqvmWBqwq8mTZFYPOyE+gSf8QluovYeC3/GUvnDkrcmRW11S4ManGL7k
2slzvfFaNlV/kHtgisA2MvK+a1DuedCmq/zvN5g1AY3LsyGw6/8clEUPdweYSzlN
lfhnkCpkLOTNUT4L493SoFZYxDUZqvU2BEcnd0CHnsIycQLXZx/iIgbIuPmwHatZ
R7iUJB0VXoERnrk9eU0Nx2az4iG4PURQvwOnbYk99FH5HVzFAwtN3vOZfTeSWWOM
Zxx8Mj6f70+UJHFGknvR
=FRzo
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.