CVE-2012-0863: Mumble

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configuration data by reading a file.

Affected products

  • Mumble Mumble: up to and including 1.2.3; version 1.2.0 only; version 1.2.2 only

Published 2012-04-30. Last modified 2026-06-16.