SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-4067

There is a leak of information between different client connections.

HIGH 7.5EPSS 1.90%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.90%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.90% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-665
Affected
coturn project/coturn · debian/debian linux · fedoraproject/fedora · canonical/ubuntu linux · opensuse/leap
Source
security-advisories@github.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.