CVE-2020-13962
Description
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSLs error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.567
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2020-13962 are affected in Mumble 1.3.0 | Windows |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-assistant-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-designer-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-doctools-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-linguist-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qdbusviewer-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-common-5.12.5-6.el8.noarch.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-debugsource-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-debugsource-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-devel-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-devel-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-examples-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-examples-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-gui-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-gui-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-mysql-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-mysql-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-odbc-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-odbc-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-postgresql-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-postgresql-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-private-devel-5.12.5-6.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtbase-private-devel-5.12.5-6.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-common-5.12.5-2.el8.noarch.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-debugsource-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-debugsource-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-devel-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-devel-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-examples-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-examples-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-libs-designer-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-libs-designer-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-libs-designercomponents-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-libs-designercomponents-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-libs-help-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qttools-libs-help-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtwebsockets-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtwebsockets-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtwebsockets-debugsource-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtwebsockets-debugsource-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtwebsockets-devel-5.12.5-2.el8.i686.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtwebsockets-devel-5.12.5-2.el8.x86_64.rpm | Linux |
| (RHSA-2020:4690) qt5-qtbase and qt5-qtwebsockets security and bug fix update qt5-qtwebsockets-examples-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-assistant update (ELSA-2020-4690) qt5-assistant-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-designer update (ELSA-2020-4690) qt5-designer-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-doctools update (ELSA-2020-4690) qt5-doctools-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-linguist update (ELSA-2020-4690) qt5-linguist-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qdbusviewer update (ELSA-2020-4690) qt5-qdbusviewer-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qtbase update (ELSA-2020-4690) qt5-qtbase-5.12.5-6.el8.i686.rpm | Linux |
| Qt5-qtbase update (ELSA-2020-4690) qt5-qtbase-5.12.5-6.el8.x86_64.rpm | Linux |
| Qt5-qtbase-common update (ELSA-2020-4690) qt5-qtbase-common-5.12.5-6.el8.noarch.rpm | Linux |
| Qt5-qtbase-devel update (ELSA-2020-4690) qt5-qtbase-devel-5.12.5-6.el8.i686.rpm | Linux |
| Qt5-qtbase-devel update (ELSA-2020-4690) qt5-qtbase-devel-5.12.5-6.el8.x86_64.rpm | Linux |
| Qt5-qtbase-examples update (ELSA-2020-4690) qt5-qtbase-examples-5.12.5-6.el8.i686.rpm | Linux |
| Qt5-qtbase-examples update (ELSA-2020-4690) qt5-qtbase-examples-5.12.5-6.el8.x86_64.rpm | Linux |
| Qt5-qtbase-gui update (ELSA-2020-4690) qt5-qtbase-gui-5.12.5-6.el8.i686.rpm | Linux |
| Qt5-qtbase-gui update (ELSA-2020-4690) qt5-qtbase-gui-5.12.5-6.el8.x86_64.rpm | Linux |
| Qt5-qtbase-mysql update (ELSA-2020-4690) qt5-qtbase-mysql-5.12.5-6.el8.i686.rpm | Linux |
| Qt5-qtbase-mysql update (ELSA-2020-4690) qt5-qtbase-mysql-5.12.5-6.el8.x86_64.rpm | Linux |
| Qt5-qtbase-odbc update (ELSA-2020-4690) qt5-qtbase-odbc-5.12.5-6.el8.i686.rpm | Linux |
| Qt5-qtbase-odbc update (ELSA-2020-4690) qt5-qtbase-odbc-5.12.5-6.el8.x86_64.rpm | Linux |
| Qt5-qtbase-postgresql update (ELSA-2020-4690) qt5-qtbase-postgresql-5.12.5-6.el8.i686.rpm | Linux |
| Qt5-qtbase-postgresql update (ELSA-2020-4690) qt5-qtbase-postgresql-5.12.5-6.el8.x86_64.rpm | Linux |
| Qt5-qtbase-private-devel update (ELSA-2020-4690) qt5-qtbase-private-devel-5.12.5-6.el8.i686.rpm | Linux |
| Qt5-qtbase-private-devel update (ELSA-2020-4690) qt5-qtbase-private-devel-5.12.5-6.el8.x86_64.rpm | Linux |
| Qt5-qttools update (ELSA-2020-4690) qt5-qttools-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qttools-common update (ELSA-2020-4690) qt5-qttools-common-5.12.5-2.el8.noarch.rpm | Linux |
| Qt5-qttools-devel update (ELSA-2020-4690) qt5-qttools-devel-5.12.5-2.el8.i686.rpm | Linux |
| Qt5-qttools-devel update (ELSA-2020-4690) qt5-qttools-devel-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qttools-examples update (ELSA-2020-4690) qt5-qttools-examples-5.12.5-2.el8.i686.rpm | Linux |
| Qt5-qttools-examples update (ELSA-2020-4690) qt5-qttools-examples-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qttools-libs-designer update (ELSA-2020-4690) qt5-qttools-libs-designer-5.12.5-2.el8.i686.rpm | Linux |
| Qt5-qttools-libs-designer update (ELSA-2020-4690) qt5-qttools-libs-designer-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qttools-libs-designercomponents update (ELSA-2020-4690) qt5-qttools-libs-designercomponents-5.12.5-2.el8.i686.rpm | Linux |
| Qt5-qttools-libs-designercomponents update (ELSA-2020-4690) qt5-qttools-libs-designercomponents-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qttools-libs-help update (ELSA-2020-4690) qt5-qttools-libs-help-5.12.5-2.el8.i686.rpm | Linux |
| Qt5-qttools-libs-help update (ELSA-2020-4690) qt5-qttools-libs-help-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qtwebsockets update (ELSA-2020-4690) qt5-qtwebsockets-5.12.5-2.el8.i686.rpm | Linux |
| Qt5-qtwebsockets update (ELSA-2020-4690) qt5-qtwebsockets-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qtwebsockets-devel update (ELSA-2020-4690) qt5-qtwebsockets-devel-5.12.5-2.el8.i686.rpm | Linux |
| Qt5-qtwebsockets-devel update (ELSA-2020-4690) qt5-qtwebsockets-devel-5.12.5-2.el8.x86_64.rpm | Linux |
| Qt5-qtwebsockets-examples update (ELSA-2020-4690) qt5-qtwebsockets-examples-5.12.5-2.el8.x86_64.rpm | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-343694 | Mumble (1.5.634) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234