High severity7.5NVD Advisory· Published Jun 9, 2020· Updated Jun 17, 2026
CVE-2020-13962
CVE-2020-13962
Description
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- Qt/Qtdescription
- osv-coords6 versionspkg:rpm/opensuse/libqt5-qtbase&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/qt5-qtbase-staticpkg:rpm/almalinux/qt5-qttools-staticpkg:rpm/suse/libqt5-qtbase&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/opensuse/libqt5-qtbase&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/libqt5-qtbase&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2
< 5.15.2+kde268-2.1+ 5 more
- (no CPE)range: < 5.15.2+kde268-2.1
- (no CPE)range: < 5.12.5-6.el8
- (no CPE)range: < 5.12.5-2.el8
- (no CPE)range: < 5.12.7-4.3.1
- (no CPE)range: < 5.12.7-lp152.3.3.1
- (no CPE)range: < 5.12.7-4.3.1
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- github.com/mumble-voip/mumble/pull/4032nvdPatchThird Party Advisory
- github.com/mumble-voip/mumble/issues/3679nvdExploitIssue TrackingPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-09/msg00004.htmlnvdMailing ListThird Party Advisory
- bugreports.qt.io/browse/QTBUG-83450nvdIssue TrackingVendor Advisory
- security.gentoo.org/glsa/202007-18nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X6EDPIIAQPVP2CHL2CHDHJ25EECA7UE/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQJDBZUYMMF4R5QQKD2HTIKQU2NSKO63/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3IZY7LKJ6NAXQDFYFR4S7L5BBHYK53K/nvd
News mentions
0No linked articles in our index yet.