[SECURITY] [DLA 2522-1] coturn security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2522-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
January 12, 2021 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : coturn
Version : 4.5.0.5-1+deb9u3
CVE ID : CVE-2020-26262
A flaw was discovered in coturn, a TURN and STUN server for VoIP. By
default coturn does not allow peers on the loopback addresses
(127.x.x.x and ::1). A remote attacker can bypass the protection via a
specially crafted request using a peer address of '0.0.0.0' and trick
coturn in relaying to the loopback interface. If listening on IPv6 the
loopback interface can also be reached by using either [::1] or [::] as
the address.
For Debian 9 stretch, this problem has been fixed in version
4.5.0.5-1+deb9u3.
We recommend that you upgrade your coturn packages.
For the detailed security status of coturn please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/coturn
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl/9YiIACgkQnUbEiOQ2
gwKOFA//ZNGTIsElSD9U/TmvtRt/HBk3BcKD43C+0gt15soWTFo2cQbdK2kc9Gik
HUaj3D9vpyPDtTJJ/IQRPKfnfYpD4Lk/pCgASE1vtnnoKkWAA/Ji00tOFcM9qYnO
lQBFdseZRyrwdZ81EE4Q6Ajqgr4yHPJS+nPZRw44gMR3kDCHMB/C/dqBeRQcY2ck
vARaE+oKFKTfCO7Aa/T17YcLhIS+OxLXpl33j96KbL60V7p+wRTTsNtV/eLeMAhO
iy0PZsHtVyFwU9oKh9nNWi+VP6Bx2fT4yfCtXAVP9jxWzorqfjGy0EVW7p7gKoeZ
u+bok308rhJh17dJQvFgAF1F4TQBV4HR+5ugGmjVW406MynnLxpoBDLQ7Py3Bn9O
A37rm2UNwRKWVyHir1oHVj6LmkEM5+p6Zl5w3N8Lioc+2Cfux6mMlBgsmmR6YCHq
Pz06HGkRx92sKpzdP5LmK0yXQDxfNKtoeffFVkHbTqh8wO4rVt3KlTc+is9FUMF5
BIGsJNo/MmMf6vzERVL1duPGaloixhgpr1GfNbHOmdAj7hr5XkCTPG57Y8n0LbPd
0CXkc21QbSt04QIjKq+ylMTWudmnLcOGqEiGIVoQevV83M8O1lvqLmcm0Egc4Oxi
zVuGa7/SNIyKRKzCyXHihY4iJAN9h8fGDdQ4eIeZmbKM619Hcvo=
=7KVB
-----END PGP SIGNATURE-----
Reply to: