CVE-2020-4067
coturn - security update
7.5
HIGH
CVSS 3.1
EPSS 1.8%
描述
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3.
如何修補 CVE-2020-4067
要修補 CVE-2020-4067,請將受影響套件升級到下列已修補版本。
- —升級至 4.5.1.3-1 或更新版本
- —升級至 4.2.1.2-1+deb8u2 或更新版本
- —升級至 4.5.0.5-1+deb9u2 或更新版本
CVE-2020-4067 正在被利用嗎?
低 — EPSS 為 1.8%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 4.5.1.3-1
- from 0, < 4.2.1.2-1+deb8u2
- from 0, < 4.5.0.5-1+deb9u2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |