<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for mumble</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2021:0300-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-02-16T11:04:47Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-02-16T11:04:47Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-02-16T11:04:47Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for mumble</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for mumble fixes the following issues:

mumble was updated to 1.3.4:

* Fix use of outdated (non-existent) notification icon names
* Fix Security vulnerability caused by allowing non http/https
  URL schemes in public server list (boo#1182123)
* Server: Fix Exit status for actions like --version or --supw
* Fix packet loss &amp; audio artifacts caused by OCB2 XEX*
  mitigation

- update apparmor profiles to get warning free again on 15.2
  - use abstractions for ssl files
  - allow inet dgram sockets as mumble can also work via udp
  - allow netlink socket (probably for dbus)
  - properly allow lsb_release again
  - add support for optional local include
- start murmurd directly as user mumble-server it gets rid of the
  dac_override/setgid/setuid/chown permissions

Update to upstream version 1.3.3

Client:

* Fixed: Chatbox invisble (zero height) (#4388)
* Fixed: Handling of invalid packet sizes (#4394)
* Fixed: Race-condition leading to loss of shortcuts (#4430)
* Fixed: Link in About dialog is now clickable again (#4454)
* Fixed: Sizing issues in ACL-Editor (#4455)
* Improved: PulseAudio now always samples at 48 kHz (#4449)

Server:

* Fixed: Crash due to problems when using PostgreSQL (#4370)
* Fixed: Handling of invalid package sizes (#4392)

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2021-300</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TRBUKSNSCDTY3U6LK6SUQ3QWJS3JDGST/</URL>
      <Description>E-Mail link for openSUSE-SU-2021:0300-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1180068</URL>
      <Description>SUSE Bug 1180068</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182123</URL>
      <Description>SUSE Bug 1182123</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 15.2">
      <Branch Type="Product Name" Name="openSUSE Leap 15.2">
        <FullProductName ProductID="openSUSE Leap 15.2" CPE="cpe:/o:opensuse:leap:15.2">openSUSE Leap 15.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="mumble-1.3.4-lp152.2.6.1">
      <FullProductName ProductID="mumble-1.3.4-lp152.2.6.1">mumble-1.3.4-lp152.2.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mumble-32bit-1.3.4-lp152.2.6.1">
      <FullProductName ProductID="mumble-32bit-1.3.4-lp152.2.6.1">mumble-32bit-1.3.4-lp152.2.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mumble-server-1.3.4-lp152.2.6.1">
      <FullProductName ProductID="mumble-server-1.3.4-lp152.2.6.1">mumble-server-1.3.4-lp152.2.6.1</FullProductName>
    </Branch>
    <Relationship ProductReference="mumble-1.3.4-lp152.2.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:mumble-1.3.4-lp152.2.6.1">mumble-1.3.4-lp152.2.6.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="mumble-32bit-1.3.4-lp152.2.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:mumble-32bit-1.3.4-lp152.2.6.1">mumble-32bit-1.3.4-lp152.2.6.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="mumble-server-1.3.4-lp152.2.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:mumble-server-1.3.4-lp152.2.6.1">mumble-server-1.3.4-lp152.2.6.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
  </ProductTree>
</cvrfdoc>
