Lucene search

K
archlinuxArchLinuxASA-202101-21
HistoryJan 12, 2021 - 12:00 a.m.

[ASA-202101-21] coturn: insufficient validation

2021-01-1200:00:00
security.archlinux.org
110
coturn
validation
loopback
attack
security
upgrade

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

EPSS

0.002

Percentile

56.7%

Arch Linux Security Advisory ASA-202101-21

Severity: High
Date : 2021-01-12
CVE-ID : CVE-2020-26262
Package : coturn
Type : insufficient validation
Remote : Yes
Link : https://security.archlinux.org/AVG-1430

Summary

The package coturn before version 4.5.2-1 is vulnerable to insufficient
validation.

Resolution

Upgrade to 4.5.2-1.

pacman -Syu “coturn>=4.5.2-1”

The problem has been fixed upstream in version 4.5.2.

Workaround

None.

Description

A security issue was found in coturn before version 4.5.2. By default
coturn does not allow peers to connect and relay packets to loopback
addresses in the range of 127.x.x.x. However, it was observed that when
sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a
successful response was received and subsequently, CONNECTIONBIND also
received a successful response. Coturn then is able to relay packets to
the loopback interface. Additionally, when coturn is listening on IPv6,
which is default, the loopback interface can also be reached by making
use of either [::1] or [::] as the peer address.

Impact

A malicious attacker might relay packets to the loopback interface due
to insufficient validation of the connection.

References

https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p
https://github.com/coturn/coturn/commit/ff5e5478a3e1b426bad053828099403cfc5c1f5f
https://github.com/coturn/coturn/commit/af50d63a152cd9505d38f02bc552848748805e7b
https://github.com/coturn/coturn/commit/6c774b9fb8d9d76576ece10a6429172ed3800466
https://github.com/coturn/coturn/commit/560684c894498285f9e4271f3c924ebf01f36307
https://github.com/coturn/coturn/commit/649cbf966181846ecdd7847e4543dd287a78d295
https://github.com/coturn/coturn/commit/9c7deff4b8ed8c323c87b9ede75481bd6bc3154d
https://github.com/coturn/coturn/commit/dd0ffdb51a4cddaf1d6662079fa91f6f32bd26a8
https://github.com/coturn/coturn/commit/d84028b6dbc9eb7d3f8828ec37ae02a0963257b6
https://security.archlinux.org/CVE-2020-26262

OSVersionArchitecturePackageVersionFilename
ArchLinuxanyanycoturn< 4.5.2-1UNKNOWN

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

EPSS

0.002

Percentile

56.7%