{"id":"MGASA-2021-0087","summary":"Updated coturn package fixes a security vulnerability","details":"When sending a CONNECT request with the XOR-PEER-ADDRESS value of 0.0.0.0, a\nmalicious user would be able to relay packets to the loopback interface.\nAdditionally, when coturn is listening on IPv6, which is default, the loopback\ninterface can also be reached by making use of either [::1] or [::] as the peer\naddress (CVE-2020-26262).\n\nIf updating is not possible, the setting --denied-peer-ip=0.0.0.0 can mitigate\nthis issue.\n\nThe coturn package has been patched to fix this issue.\n","modified":"2026-04-16T04:44:19.027969426Z","published":"2021-02-19T10:27:54Z","upstream":["CVE-2020-26262"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0087.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28068"},{"type":"ADVISORY","url":"https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p"}],"affected":[{"package":{"name":"coturn","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/coturn?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.2-1.4.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0087.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}