ZeroHour

CVE-2020-6061

PoC
CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.

Vendors
coturn projectfedoraprojectdebiancanonical
Products
coturn, fedora, debian linux, ubuntu linux
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news