CVE-2020-4067: Improper Initialization in coturn
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/coturnto a version that resolves this vulnerability.Fixed in 4.5.2-3Fixed in 4.6.1-1Fixed in 4.6.1-2Fixed in 4.12.0-1 - Upgrade
Upgrade
coturnto a version that resolves this vulnerability.Fixed in 4.5.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4067?
CVE-2020-4067 has been classified as a medium severity vulnerability due to the potential for information leakage between client connections.
How do I fix CVE-2020-4067?
To fix CVE-2020-4067, upgrade to coturn version 4.5.1.3 or later.
What kind of systems are affected by CVE-2020-4067?
CVE-2020-4067 affects coturn versions prior to 4.5.1.3 on Ubuntu, Debian, and Fedora systems.
What is the nature of the vulnerability described in CVE-2020-4067?
CVE-2020-4067 is a vulnerability that involves the improper initialization of STUN/TURN response buffers, leading to potential information leaks.
Can an attacker exploit CVE-2020-4067 remotely?
Yes, an attacker can exploit CVE-2020-4067 remotely by querying the coturn server to access sensitive information from other client connections.