It was discovered [1] that the Mumble client is vulnerable to a Denial of Service attack when rendering crafted SVG files that contain references to files on the local computer. This can cause the Mumble client to hang and/or become resource exhausted. This issue can be triggered remotely by an entity participating in a Mumble voice chat. Triggering the issue remotely can be done using text messages, channel comments, user comments and user textures/avatars. [1]: http://mumble.info/security/Mumble-SA-2014-005.txt
mumble-1.2.6-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
mumble-1.2.6-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.