PublicDateAtUSN: 2021-01-11 00:00:00 UTC
Candidate: CVE-2020-26262
CRD: 2021-01-11 00:00:00 UTC
PublicDate: 2021-01-13 19:15:00 UTC
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26262
 https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p
 https://ubuntu.com/security/notices/USN-4690-1
Description:
 Coturn is free open source implementation of TURN and STUN Server. Coturn
 before version 4.5.2 by default does not allow peers to connect and relay
 packets to loopback addresses in the range of `127.x.x.x`. However, it was
 observed that when sending a `CONNECT` request with the `XOR-PEER-ADDRESS`
 value of `0.0.0.0`, a successful response was received and subsequently,
 `CONNECTIONBIND` also received a successful response. Coturn then is able
 to relay packets to the loopback interface. Additionally, when coturn is
 listening on IPv6, which is default, the loopback interface can also be
 reached by making use of either `[::1]` or `[::]` as the peer address. By
 using the address `0.0.0.0` as the peer address, a malicious user will be
 able to relay packets to the loopback interface, unless
 `--denied-peer-ip=0.0.0.0` (or similar) has been specified. Since the
 default configuration implies that loopback peers are not allowed, coturn
 administrators may choose to not set the `denied-peer-ip` setting. The
 issue patched in version 4.5.2. As a workaround the addresses in the
 address block `0.0.0.0/8`, `[::1]` and `[::]` should be denied by default
 unless `--allow-loopback-peers` has been specified.
Ubuntu-Description:
Notes:
 pfsmorigo| Tested vulnerable versions: 4.5.1.3
Mitigation:
Bugs:
Priority: medium
Discovered-by:
Assigned-to: pfsmorigo
CVSS:
 nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N [7.2 HIGH]


Patches_coturn:
upstream_coturn: needs-triage
precise/esm_coturn: DNE
trusty_coturn: ignored (out of standard support)
trusty/esm_coturn: DNE
xenial_coturn: released (4.5.0.3-1ubuntu0.4)
bionic_coturn: released (4.5.0.7-1ubuntu2.18.04.3)
focal_coturn: released (4.5.1.1-1.1ubuntu0.20.04.2)
groovy_coturn: released (4.5.1.3-1ubuntu0.1)
devel_coturn: released (4.5.1.3-1ubuntu1)
