CVE-2020-4067
Last modified
CVE-2020-4067 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. EPSS estimates a 1.85% chance of exploitation in the next 30 days.
Description
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Coturn Project | Coturn | < 4.5.1.3 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Fedoraproject | Fedora | 31 |
| Fedoraproject | Fedora | 32 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.10 |
| Canonical | Ubuntu Linux | 20.04 |
| Opensuse | Leap | 15.2 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00010.htmlMailing List, Third Party Advisory
- https://github.com/coturn/coturn/issues/583Issue Tracking, Third Party Advisory
- https://github.com/coturn/coturn/security/advisories/GHSA-c8r8-8vp5-6gcmThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00002.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/4415-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4711Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00010.htmlMailing List, Third Party Advisory
- https://github.com/coturn/coturn/issues/583Issue Tracking, Third Party Advisory
- https://github.com/coturn/coturn/security/advisories/GHSA-c8r8-8vp5-6gcmThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00002.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/4415-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4711Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-4067?
How severe is CVE-2020-4067?
How do I fix CVE-2020-4067?
Are you affected by CVE-2020-4067?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
