CVE-2020-4067
Summary
| CVE | CVE-2020-4067 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-29 20:15:00 UTC |
| Updated | 2023-11-07 03:23:00 UTC |
| Description | In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: coturn-4.5.1.3-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| USN-4415-1: coTURN vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| STUN response buffer not initialized properly · Advisory · coturn/coturn · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| [SECURITY] Fedora 31 Update: coturn-4.5.1.3-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2020:0937-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| Reporting a security issue: CVE-2020-4067 · Issue #583 · coturn/coturn · GitHub |
MISC |
github.com |
Third Party Advisory |
| [SECURITY] [DLA 2271-1] coturn security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 32 Update: coturn-4.5.1.3-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| coturn/ChangeLog at aab60340b201d55c007bcdc853230f47aa2dfdf1 · coturn/coturn · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| Debian -- Security Information -- DSA-4711-1 coturn |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: coturn-4.5.1.3-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500860 Alpine Linux Security Update for coturn
- 504652 Alpine Linux Security Update for coturn