Vulnerability CVE-2020-6061: Information
Description
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.
Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
coturn | sisyphus | 4.5.1.1-alt2 | 4.6.2-alt1 | ALT-PU-2020-1668-1 | 249416 | Fixed |
coturn | sisyphus_e2k | 4.5.2-alt1 | 4.6.2-alt1 | ALT-PU-2021-4640-1 | - | Fixed |
coturn | p10 | 4.5.2-alt1 | 4.5.2-alt1 | ALT-PU-2022-2460-1 | 305002 | Fixed |
coturn | p10_e2k | 4.5.2-alt1 | 4.5.2-alt1 | ALT-PU-2022-5899-1 | - | Fixed |
coturn | p9 | 4.5.1.1-alt2 | 4.5.1.1-alt2 | ALT-PU-2020-1668-1 | 249416 | Fixed |
coturn | c10f2 | 4.5.2-alt1 | 4.5.2-alt1 | ALT-PU-2022-2460-1 | 305002 | Fixed |
coturn | p11 | 4.5.1.1-alt2 | 4.6.2-alt1 | ALT-PU-2020-1668-1 | 249416 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
FEDORA-2020-f3fcb1608a | |
FEDORA-2020-f3fcb1608a | |
FEDORA-2020-6efa0fc869 | |
FEDORA-2020-6efa0fc869 | |
FEDORA-2020-305c173af8 | |
FEDORA-2020-305c173af8 | |
https://talosintelligence.com/vulnerability_reports/TALOS-2020-0984 |
|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-0984 |
|
USN-4415-1 |
|
USN-4415-1 |
|
DSA-4711 |
|
DSA-4711 |
|