Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 765157 (CVE-2020-26262)

Summary: <net-im/coturn-4.5.2: Loopback bypass (CVE-2020-26262)
Product: Gentoo Security Reporter: Kenton Groombridge <concord>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: jstein, nativemad
Priority: Normal Keywords: PullRequest
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p
See Also: https://github.com/gentoo/gentoo/pull/19539
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description Kenton Groombridge gentoo-dev 2021-01-12 20:43:03 UTC
By default coturn does not allow peers to connect and relay packets to loopback addresses in the range of 127.x.x.x. However, it was observed that when sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a successful response was received and subsequently, CONNECTIONBIND also received a successful response. Coturn then is able to relay packets to the loopback interface.

Additionally, when coturn is listening on IPv6, which is default, the loopback interface can also be reached by making use of either [::1] or [::] as the peer address.

https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-12 20:48:30 UTC
Thanks for the report! They're really helpful for keeping on top of various vulnerabilities in packages, especially when they haven't received a (public) CVE yet.

I've adjusted the summary because we don't version them until we have a fixed version in Gentoo.

@maintainer, please bump to 4.5.2.
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-01-26 03:09:39 UTC
ping
Comment 3 Andreas Schürch gentoo-dev 2021-02-26 12:54:18 UTC
I bumped the ebuild to 4.5.2 and removed the old version now.
Sorry for the delay!
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-02-26 16:37:26 UTC
(In reply to Andreas Schürch from comment #3)
> I bumped the ebuild to 4.5.2 and removed the old version now.
> Sorry for the delay!

Thanks! Tree is clean, all done.
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:24:37 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 17:33:08 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 17:40:59 UTC Comment hidden (obsolete)
Comment 8 NATTkA bot gentoo-dev 2021-07-29 17:49:09 UTC Comment hidden (obsolete)
Comment 9 NATTkA bot gentoo-dev 2021-07-29 18:05:04 UTC Comment hidden (obsolete)
Comment 10 NATTkA bot gentoo-dev 2021-07-29 18:13:22 UTC
Package list is empty or all packages have requested keywords.