[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2522-1] coturn security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2522-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/               Emilio Pozuelo Monfort
January 12, 2021                              https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : coturn
Version        : 4.5.0.5-1+deb9u3
CVE ID         : CVE-2020-26262

A flaw was discovered in coturn, a TURN and STUN server for VoIP. By
default coturn does not allow peers on the loopback addresses
(127.x.x.x and ::1). A remote attacker can bypass the protection via a
specially crafted request using a peer address of '0.0.0.0' and trick
coturn in relaying to the loopback interface. If listening on IPv6 the
loopback interface can also be reached by using either [::1] or [::] as
the address.

For Debian 9 stretch, this problem has been fixed in version
4.5.0.5-1+deb9u3.

We recommend that you upgrade your coturn packages.

For the detailed security status of coturn please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/coturn

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl/9YiIACgkQnUbEiOQ2
gwKOFA//ZNGTIsElSD9U/TmvtRt/HBk3BcKD43C+0gt15soWTFo2cQbdK2kc9Gik
HUaj3D9vpyPDtTJJ/IQRPKfnfYpD4Lk/pCgASE1vtnnoKkWAA/Ji00tOFcM9qYnO
lQBFdseZRyrwdZ81EE4Q6Ajqgr4yHPJS+nPZRw44gMR3kDCHMB/C/dqBeRQcY2ck
vARaE+oKFKTfCO7Aa/T17YcLhIS+OxLXpl33j96KbL60V7p+wRTTsNtV/eLeMAhO
iy0PZsHtVyFwU9oKh9nNWi+VP6Bx2fT4yfCtXAVP9jxWzorqfjGy0EVW7p7gKoeZ
u+bok308rhJh17dJQvFgAF1F4TQBV4HR+5ugGmjVW406MynnLxpoBDLQ7Py3Bn9O
A37rm2UNwRKWVyHir1oHVj6LmkEM5+p6Zl5w3N8Lioc+2Cfux6mMlBgsmmR6YCHq
Pz06HGkRx92sKpzdP5LmK0yXQDxfNKtoeffFVkHbTqh8wO4rVt3KlTc+is9FUMF5
BIGsJNo/MmMf6vzERVL1duPGaloixhgpr1GfNbHOmdAj7hr5XkCTPG57Y8n0LbPd
0CXkc21QbSt04QIjKq+ylMTWudmnLcOGqEiGIVoQevV83M8O1lvqLmcm0Egc4Oxi
zVuGa7/SNIyKRKzCyXHihY4iJAN9h8fGDdQ4eIeZmbKM619Hcvo=
=7KVB
-----END PGP SIGNATURE-----


Reply to: