Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian 8 DLA-1671-1 Critical: coturn Multiple Threats Addressed

debian lts
Calendar Grey February 11, 2019
Dist Debian Esm H88
Important coturn patch for Debian 8 addresses several security flaws improving overall protection. Upgrade suggested.
Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP

Summary

An SQL injection vulnerability was discovered in the coTURN administrator
web portal. As the administration web interface is shared with the
production, it is unfortunately not possible to easily filter outside
access and this security update completely disables the web interface. Users should use the local, command line interface instead.

CVE-2018-4058

Default configuration enables unsafe loopback forwarding. A remote attacker
with access to the TURN interface can use this vulnerability to gain access
to services that should be local only.

CVE-2018-4059

Default configuration uses an empty password for the local command line
administration interface. An attacker with access to the local console
(either a local attacker or a remote attacker taking advantage of
CVE-2018-4058) could escalade privileges to administrator of the coTURN
server.

For Debian 8 "Jessie", these problems have been fixed in version
4.2.1.2-1+deb8u1.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: coturn
Version: 4.2.1.2-1+deb8u1
CVE ID: CVE-2018-4056 CVE-2018-4058 CVE-2018-4059

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here