-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2522-1 debian-...@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort January 12, 2021 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : coturn Version : 4.5.0.5-1+deb9u3 CVE ID : CVE-2020-26262 A flaw was discovered in coturn, a TURN and STUN server for VoIP. By default coturn does not allow peers on the loopback addresses (127.x.x.x and ::1). A remote attacker can bypass the protection via a specially crafted request using a peer address of '0.0.0.0' and trick coturn in relaying to the loopback interface. If listening on IPv6 the loopback interface can also be reached by using either [::1] or [::] as the address. For Debian 9 stretch, this problem has been fixed in version 4.5.0.5-1+deb9u3. We recommend that you upgrade your coturn packages. For the detailed security status of coturn please refer to its security tracker page at: https://security-tracker.debian.org/tracker/coturn Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl/9YiIACgkQnUbEiOQ2 gwKOFA//ZNGTIsElSD9U/TmvtRt/HBk3BcKD43C+0gt15soWTFo2cQbdK2kc9Gik HUaj3D9vpyPDtTJJ/IQRPKfnfYpD4Lk/pCgASE1vtnnoKkWAA/Ji00tOFcM9qYnO lQBFdseZRyrwdZ81EE4Q6Ajqgr4yHPJS+nPZRw44gMR3kDCHMB/C/dqBeRQcY2ck vARaE+oKFKTfCO7Aa/T17YcLhIS+OxLXpl33j96KbL60V7p+wRTTsNtV/eLeMAhO iy0PZsHtVyFwU9oKh9nNWi+VP6Bx2fT4yfCtXAVP9jxWzorqfjGy0EVW7p7gKoeZ u+bok308rhJh17dJQvFgAF1F4TQBV4HR+5ugGmjVW406MynnLxpoBDLQ7Py3Bn9O A37rm2UNwRKWVyHir1oHVj6LmkEM5+p6Zl5w3N8Lioc+2Cfux6mMlBgsmmR6YCHq Pz06HGkRx92sKpzdP5LmK0yXQDxfNKtoeffFVkHbTqh8wO4rVt3KlTc+is9FUMF5 BIGsJNo/MmMf6vzERVL1duPGaloixhgpr1GfNbHOmdAj7hr5XkCTPG57Y8n0LbPd 0CXkc21QbSt04QIjKq+ylMTWudmnLcOGqEiGIVoQevV83M8O1lvqLmcm0Egc4Oxi zVuGa7/SNIyKRKzCyXHihY4iJAN9h8fGDdQ4eIeZmbKM619Hcvo= =7KVB -----END PGP SIGNATURE-----