When sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a
malicious user would be able to relay packets to the loopback interface.
Additionally, when coturn is listening on IPv6, which is default, the loopback
interface can also be reached by making use of either [::1] or [::] as the peer
address (CVE-2020-26262).
If updating is not possible, the setting --denied-peer-ip=0.0.0.0 can mitigate
this issue.
The coturn package has been patched to fix this issue.
- https://bugs.mageia.org/show_bug.cgi?id=28068
- https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p
- https://www.cve.org/CVERecord?id=CVE-2020-26262
- 7/core/coturn-4.5.2-1.4.mga7
Get the latest Linux and open source security news straight to your inbox.