Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA-4373-1 Critical: coTURN SQL Injection and Access Issues

debian
Calendar Grey January 28, 2019
Debian Logo
- ------------------------------------------------------------------------- Debian Security Advisory
Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP

Summary

CVE-2018-4056

An SQL injection vulnerability was discovered in the coTURN administrator
web portal. As the administration web interface is shared with the
production, it is unfortunately not possible to easily filter outside
access and this security update completely disable the web interface. Users should use the local, command line interface instead.

CVE-2018-4058

Default configuration enables unsafe loopback forwarding. A remote attacker
with access to the TURN interface can use this vulnerability to gain access
to services that should be local only.

CVE-2018-4059

Default configuration uses an empty password for the local command line
administration interface. An attacker with access to the local console
(either a local attacker or a remote attacker taking advantage of
CVE-2018-4058) could escalade privileges to administrator of the coTURN
server.

For the stable distribution (stretch), these problems have been fixed in
version 4.5.0.5-1+deb9u1.

W...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: coturn
CVE ID: CVE-2018-4056 CVE-2018-4058 CVE-2018-4059

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here