Improper Initialization in coturn
CVE-2020-4067

7HIGH

Key Information:

Vendor

Coturn

Status
Vendor
CVE Published:
29 June 2020

What is CVE-2020-4067?

In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3.

Affected Version(s)

coturn >= 5.1.1, < 6.0.0

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.