When sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a malicious user would be able to relay packets to the loopback interface. Additionally, when coturn is listening on IPv6, which is default, the loopback interface can also be reached by making use of either [::1] or [::] as the peer address (CVE-2020-26262). . MGASA-2021-0087 - Updated coturn package fixes a security vulnerability Publication date: 19 Feb 2021 URL: https://advisories.mageia.org/MGASA-2021-0087.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-26262 When sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a malicious user would be able to relay packets to the loopback interface. Additionally, when coturn is listening on IPv6, which is default, the loopback interface can also be reached by making use of either [::1] or [::] as the peer address (CVE-2020-26262). If updating is not possible, the setting --denied-peer-ip=0.0.0.0 can mitigate this issue. The coturn package has been patched to fix this issue. References: - https://bugs.mageia.org/show_bug.cgi?id=28068 - https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p - https://www.cve.org/CVERecord?id=CVE-2020-26262 SRPMS: - 7/core/coturn-4.5.2-1.4.mga7 . The recent patch addresses a security flaw in coturn that permits packet relaying to the loopback interface. Please review the available mitigation strategies.. Mageia Coturn Security,Packed Relay Threat Mitigation,Coturn Update Instructions. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.