Coturn是Coturn组织开源的一款实现TURN协议的服务器软件。 Coturn 4.15.0之前版本存在数字错误漏洞,该漏洞源于src/client/ns_turn_msg.c文件中的stun_get_message_len_str()函数对STUN消息body-length字段处理不当导致整数溢出,可能允许未经身份验证的远程攻击者通过TCP或TLS发送特制STUN消息,导致流解析器失步并断开攻击客户端连接,造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68553 | 7.1 HIGH | Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command |
| CVE-2026-68555 | 6.5 MEDIUM | coturn: Chained mobility resumes allow authenticated remote memory exhaustion |
| CVE-2026-68554 | 2.3 LOW | Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers m |
No comments yet