Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)
Vulnerability Description
Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single ordinary HTTP GET request and receive a 301 response whose Location header contains up to ~870 bytes of adjacent process heap memory. The leaked region is a recycled network receive buffer that is reused without being zeroed, so on a busy server it can contain data from other clients' requests (TURN credentials, OAuth tokens, relayed payloads). Root cause is a signed→unsigned conversion. This issue is fixed in version 4.15.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
跨界内存读
Vulnerability Title
Coturn 缓冲区错误漏洞
Vulnerability Description
Coturn是Coturn组织开源的一款TURN(VoIP媒体业务NAT穿越服务器和网关)和STUN(用户数据报协议简单穿越网络地址转换器)Server的开源实现。 Coturn 4.5.2版本至4.14.0版本存在安全漏洞,该漏洞源于有符号到无符号转换错误,可能导致未经身份验证的远程客户端发送单个HTTP GET请求,获取包含相邻进程堆内存的301响应,泄漏回收未清零的网络接收缓冲区中的敏感数据(如TURN凭据、OAuth令牌)。
CVSS Information
N/A
Vulnerability Type
N/A