USN-4415-1: coTURN vulnerabilities
06 July 2020
Several security issues were fixed in coTURN.
Releases
Packages
- coturn - TURN and STUN fun88体育 for VoIP
Details
Felix Dörre discovered that coTURN response buffer is not initialized properly.
An attacker could possibly use this issue to obtain sensitive information.
(CVE-2020-4067)
It was discovered that coTURN web fun88体育 incorrectly handled HTTP POST requests.
An attacker could possibly use this issue to cause a denial of service, obtain
sensitive information or other unspecified impact.
(CVE-2020-6061, CVE-2020-6062)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
-
Ubuntu 19.10
-
-
Ubuntu 18.04
-
-
Ubuntu 16.04
-
-
In general, a standard system update will make all the necessary changes.