← Retour à la recherche de CVE

CVE-2026-68552

coturn

Description

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len variable in stun_get_message_len_str() in src/client/ns_turn_msg.c to wrap when STUN_HEADER_LENGTH is added. The framing layer then consumes only 4 through 16 bytes, treats the remaining bytes as another message, desynchronizes the stream parser, and drops the attacking client-s connection. Other clients and the server process are not affected. This issue is fixed in version 4.15.0.

CVSS 5.3EPSS 0.315%Risque 0.55
Voir la source
Publication
2026-08-19 21:17:28
Versions concernées
<4.15.0
Type
Logiciel critique
Dernière modification
2026-08-21 22:16:43
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L