CVE-2020-6061: Critical severity Coturn Project Coturn vulnerability
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/coturnto a version that resolves this vulnerability.Fixed in 4.5.1.1-1.2Fixed in 4.5.0.5-1+deb9u2Fixed in 4.5.1.1-1.1+deb10u1 - Upgrade
Upgrade
debian/coturnto a version that resolves this vulnerability.Fixed in 4.5.2-3Fixed in 4.6.1-1Fixed in 4.6.1-2Fixed in 4.12.0-1
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6061?
CVE-2020-6061 is classified as a medium severity vulnerability due to its potential for information leaks.
How do I fix CVE-2020-6061?
To fix CVE-2020-6061, upgrade to the appropriate patched version of CoTURN, such as 4.5.1.1-1.2 or later.
What versions of CoTURN are affected by CVE-2020-6061?
Versions of CoTURN prior to 4.5.1.1-1.2 are affected by CVE-2020-6061.
What type of vulnerability is CVE-2020-6061?
CVE-2020-6061 is a heap out-of-bounds read vulnerability.
What is required to exploit CVE-2020-6061?
An attacker must send a specially crafted HTTPS POST request to exploit CVE-2020-6061.