-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2411-1 security@xxxxxxxxxx http://www.debian.org/security/ Florian Weimer February 19, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mumble Vulnerability : information disclosure Problem type : local Debian-specific: no CVE ID : CVE-2012-0863 Debian Bug : 659039 It was discovered that mumble, a VoIP client, does not probably manage permission on its user-specific configuration files, allowing other local users on the system to access them. For the stable distribution (squeeze), this problem has been fixed in version 1.2.2-6+squeeze1. For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 1.2.3-3. We recommend that you upgrade your mumble packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQEcBAEBAgAGBQJPQQ0XAAoJEL97/wQC1SS+0YEH/0joT00TF14zG+fNGPe/pk1y d9ggWa/RFFnkJuFV/ckWbB9jyCcxWb518mi3SQsRYNYbLZDexh6KCNSWZFttoc/Z LDYjUjODnP4ZP1mNk5sXU8lXuk+G5vW3Pz0KyyD5XurlUJhPq+KG++YEHZrB0ow4 Vr1xiVruMpWjMzUieBhxLrVvgodRwYg9mqlsSxoFzACm0XtV73ZQV9ZAvDUKvoxO KBk4SJBjvLzfT4XN106qRW/rwMCEVPXqj+K89G8A9cMaEwhSGiaMpjHMcXgga6QY 1m7fFnyHnWcp8S++DC8WX03zD1A8BbhRKEf9DU6SHL3+tXyGkMMR1CSsaiPuF8U= =t/7S -----END PGP SIGNATURE-----