CVE-2014-3755
EPSS 1.1%
Description
The QSvg module in Qt, as used in the Mumble client 1.2.x before 1.2.6, allows remote attackers to cause a denial of service (hang and resource consumption) via a local file reference in an (1) image tag or (2) XML stylesheet in an SVG file.
How to fix CVE-2014-3755
To remediate CVE-2014-3755, upgrade the affected package to a fixed version below.
- Debian/mumble—upgrade to 1.2.6-1 or later
Is CVE-2014-3755 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.2.6-1