Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 7: MGASA-2020-0254 Critical: Coturn Heap Overflow, DoS Issues

mageia
Calendar Grey June 10, 2020
Dist Mageia Esm H88
Fresh coturn updates in Mageia resolve heap overflow vulnerabilities and mitigate denial of service risks stemming from HTTP POST requests.
Updated the coturn package in order to fix some security vulnerabilities: http_server.c: An exploitable heap overflow vulnerability exists in the way CoTURN 4.5.1.1 web server par...

Summary

Updated the coturn package in order to fix some security vulnerabilities:
http_server.c: An exploitable heap overflow vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability (CVE-2020-6061).
http_server.c An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability (CVE-2020-6062).

References

- https://bugs.mageia.org/show_bug.cgi?id=26413

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/XN2NK6FT7AMW5UIZNXDNHKEAYWAUMGSF/

- https://www.cve.org/CVERecord?id=CVE-2020-6061

- https://www.cve.org/CVERecord?id=CVE-2020-6062

Resolution

SRPMS

- 7/core/coturn-4.5.0.7-2.3.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0254.html
Type: security
CVE: CVE-2020-6061, CVE-2020-6062

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here