Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 7 MGASA-2021-0087: Critical Packet Relay Threat in Coturn

mageia
Calendar Grey February 19, 2021
Dist Mageia Esm H88
The recent patch addresses a security flaw in coturn that permits packet relaying to the loopback interface. Please review the available mitigation strategies.
When sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a malicious user would be able to relay packets to the loopback interface

Summary

When sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a malicious user would be able to relay packets to the loopback interface. Additionally, when coturn is listening on IPv6, which is default, the loopback interface can also be reached by making use of either [::1] or [::] as the peer address (CVE-2020-26262).
If updating is not possible, the setting --denied-peer-ip=0.0.0.0 can mitigate this issue.
The coturn package has been patched to fix this issue.

References

- https://bugs.mageia.org/show_bug.cgi?id=28068

- https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p

- https://www.cve.org/CVERecord?id=CVE-2020-26262

Resolution

SRPMS

- 7/core/coturn-4.5.2-1.4.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 19 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0087.html
Type: security
CVE: CVE-2020-26262

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here