HIGH
Improper Initialization in coturn
Published Jun 29, 2020
7.5
HIGHCVSS 3.1
EPSS 1.90%
Description
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3.
Affected products
-
- Version >= 5.1.1, < 6.0.0StatusaffectedConstraints-
- Version
Configuration 1
- < 4.5.1.3
Configuration 2
OR
- 8.0
- 9.0
- 10.0
Configuration 3
OR
- 31
- 32
Configuration 4
OR
- 16.04
- 18.04
- 19.10
- 20.04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://github.com/coturn/coturn/blob/aab60340b201d55c007bcdc853230f47aa2dfdf1/ChangeLog#L15 x_refsource_MISCRelease Notes
- https://github.com/coturn/coturn/issues/583 x_refsource_MISCIssue TrackingThird Party Advisory
- https://github.com/coturn/coturn/security/advisories/GHSA-c8r8-8vp5-6gcm x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00002.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5G35UBNSRLL6SYRTODYTMBJ65TLQILUM/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNJJO77ZLGGFJWNUGP6VDG5HPAC5UDBK/ vendor-advisoryx_refsource_FEDORA
- https://usn.ubuntu.com/4415-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.debian.org/security/2020/dsa-4711 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 29, 2020
Updated Aug 4, 2024
Reserved Dec 30, 2019
Link CVE-2020-4067
CISA Vulnrichment
Updated n/a