Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-27229.json"
[
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mumble-voip/mumble/commit/e59ee87abe249f345908c7d568f6879d16bfd648",
"digest": {
"function_hash": "65394302460783050181570692291240513141",
"length": 235.0
},
"id": "CVE-2021-27229-43ff6295",
"deprecated": false,
"target": {
"file": "src/mumble/ConnectDialog.cpp",
"function": "ConnectDialog::on_qaUrl_triggered"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mumble-voip/mumble/commit/e59ee87abe249f345908c7d568f6879d16bfd648",
"digest": {
"line_hashes": [
"70232847151359564456171497302430397879",
"118246664800755243633469300694518903283",
"204380696076314686599292659447017158641",
"4568989370343213662826175788362273508",
"99591226523144294550551577742778135793",
"138481416414352192922181994546856922670",
"224021822537927809128536996686578903981"
],
"threshold": 0.9
},
"id": "CVE-2021-27229-9598d386",
"deprecated": false,
"target": {
"file": "src/mumble/ConnectDialog.cpp"
}
}
]