Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 765157 (CVE-2020-26262) - <net-im/coturn-4.5.2: Loopback bypass (CVE-2020-26262)
Summary: <net-im/coturn-4.5.2: Loopback bypass (CVE-2020-26262)
Status: IN_PROGRESS
Alias: CVE-2020-26262
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/coturn/coturn/secu...
Whiteboard: ~4 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2021-01-12 20:43 UTC by 0xC0ncord
Modified: 2021-07-29 18:13 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 0xC0ncord 2021-01-12 20:43:03 UTC
By default coturn does not allow peers to connect and relay packets to loopback addresses in the range of 127.x.x.x. However, it was observed that when sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a successful response was received and subsequently, CONNECTIONBIND also received a successful response. Coturn then is able to relay packets to the loopback interface.

Additionally, when coturn is listening on IPv6, which is default, the loopback interface can also be reached by making use of either [::1] or [::] as the peer address.

https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p
Comment 1 Sam James archtester gentoo-dev Security 2021-01-12 20:48:30 UTC
Thanks for the report! They're really helpful for keeping on top of various vulnerabilities in packages, especially when they haven't received a (public) CVE yet.

I've adjusted the summary because we don't version them until we have a fixed version in Gentoo.

@maintainer, please bump to 4.5.2.
Comment 2 Sam James archtester gentoo-dev Security 2021-01-26 03:09:39 UTC
ping
Comment 3 Andreas Schürch gentoo-dev 2021-02-26 12:54:18 UTC
I bumped the ebuild to 4.5.2 and removed the old version now.
Sorry for the delay!
Comment 4 John Helmert III gentoo-dev Security 2021-02-26 16:37:26 UTC
(In reply to Andreas Schürch from comment #3)
> I bumped the ebuild to 4.5.2 and removed the old version now.
> Sorry for the delay!

Thanks! Tree is clean, all done.
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:24:37 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 17:33:08 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 17:40:59 UTC Comment hidden (obsolete)
Comment 8 NATTkA bot gentoo-dev 2021-07-29 17:49:09 UTC Comment hidden (obsolete)
Comment 9 NATTkA bot gentoo-dev 2021-07-29 18:05:04 UTC Comment hidden (obsolete)
Comment 10 NATTkA bot gentoo-dev 2021-07-29 18:13:22 UTC
Package list is empty or all packages have requested keywords.