Arch Linux Security Advisory ASA-202101-21 ========================================== Severity: High Date : 2021-01-12 CVE-ID : CVE-2020-26262 Package : coturn Type : insufficient validation Remote : Yes Link : https://security.archlinux.org/AVG-1430 Summary ======= The package coturn before version 4.5.2-1 is vulnerable to insufficient validation. Resolution ========== Upgrade to 4.5.2-1. # pacman -Syu "coturn>=4.5.2-1" The problem has been fixed upstream in version 4.5.2. Workaround ========== None. Description =========== A security issue was found in coturn before version 4.5.2. By default coturn does not allow peers to connect and relay packets to loopback addresses in the range of 127.x.x.x. However, it was observed that when sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a successful response was received and subsequently, CONNECTIONBIND also received a successful response. Coturn then is able to relay packets to the loopback interface. Additionally, when coturn is listening on IPv6, which is default, the loopback interface can also be reached by making use of either [::1] or [::] as the peer address. Impact ====== A malicious attacker might relay packets to the loopback interface due to insufficient validation of the connection. References ========== https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p https://github.com/coturn/coturn/commit/ff5e5478a3e1b426bad053828099403cfc5c... https://github.com/coturn/coturn/commit/af50d63a152cd9505d38f02bc55284874880... https://github.com/coturn/coturn/commit/6c774b9fb8d9d76576ece10a6429172ed380... https://github.com/coturn/coturn/commit/560684c894498285f9e4271f3c924ebf01f3... https://github.com/coturn/coturn/commit/649cbf966181846ecdd7847e4543dd287a78... https://github.com/coturn/coturn/commit/9c7deff4b8ed8c323c87b9ede75481bd6bc3... https://github.com/coturn/coturn/commit/dd0ffdb51a4cddaf1d6662079fa91f6f32bd... https://github.com/coturn/coturn/commit/d84028b6dbc9eb7d3f8828ec37ae02a09632... https://security.archlinux.org/CVE-2020-26262