coturn 4.5.1.1-1.1ubuntu0.20.04.1 source package in Ubuntu

Changelog

coturn (4.5.1.1-1.1ubuntu0.20.04.1) focal-security; urgency=medium

  * SECURITY UPDATE: Heap-buffer overflow in HTTP POST request
    - debian/patches/CVE-2020-6061.patch: Fix overflow
    - CVE-2020-6061
  * SECURITY UPDATE: DoS when parsing certain HTTP POST request
    - debian/patches/CVE-2020-6062.patch: Fix parsing of POST requests
    - CVE-2020-6062
  * SECURITY UPDATE: Information leak between different client connections
    - debian/patches/CVE-2020-4067.patch: initialize with zero any new or
      reused stun buffers
    - CVE-2020-4067

 -- Eduardo Barretto <email address hidden>  Thu, 02 Jul 2020 10:34:50 -0300

Upload details

Uploaded by:
Eduardo Barretto
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
coturn_4.5.1.1.orig.tar.gz 413.2 KiB e020ce90ea0301213451d37099185ff25d93f97fa0f2b48bf21b2946fc3696a4
coturn_4.5.1.1-1.1ubuntu0.20.04.1.debian.tar.xz 12.9 KiB 821936360c06a93779e50ba6266b26f1f367899b74f35c286a2a67051c38601c
coturn_4.5.1.1-1.1ubuntu0.20.04.1.dsc 2.3 KiB 36287639dfaa218dbe36eee12f709842a713825ec73d15c47f2dd313b15d9d70

View changes file

Binary packages built by this source

coturn: TURN and STUN server for VoIP

 STUN (Session Traversal Utilities for NAT) and TURN (Traversal Using Relays
 around NAT) are protocols that can be used to provide NAT traversal for VoIP
 and WebRTC. This package provides a VoIP media traffic NAT traversal server
 and gateway.
 .
 Supported RFCs:
 TURN specs:
  * RFC 5766 - base TURN specs;
  * RFC 6062 - TCP relaying TURN extension;
  * RFC 6156 - IPv6 extension for TURN;
  * RFC 7635 - OAuth third-party TURN/STUN authorization;
  * DTLS support as client protocol
    http://tools.ietf.org/html/draft-petithuguenin-tram-turn-dtls-00
  * Mobile ICE (MICE) support
    http://tools.ietf.org/html/draft-wing-tram-turn-mobility-03
  * TURN ORIGIN specs for multi-tenant servers
    http://tools.ietf.org/html/draft-johnston-tram-stun-origin-02
  * TURN Bandwidth draft specs
    http://tools.ietf.org/html/draft-thomson-tram-turn-bandwidth-00
  * SSODA (dual allocation) draft specs
    http://tools.ietf.org/html/draft-martinsen-tram-ssoda-00
 .
 STUN specs:
  * RFC 3489 - obsolete "classic" STUN specs;
  * RFC 5389 - base "new" STUN specs;
  * RFC 5769 - test vectors for STUN protocol testing;
  * RFC 5780 - NAT behavior discovery support.
 .
 The implementation fully supports UDP, TCP, TLS, and DTLS as protocols between
 the TURN client and the TURN server. Both UDP and TCP relaying are supported.
 .
 SQLite, MySQL, PostgreSQL and Redis are supported for the user
 repository (if authentication is required).
 The long-term credentials mechanism is supported.
 For WebRTC applications,
 the TURN server REST API for time-limited
 secret-based authentication is implemented.
 The third-party authentication
 specs (OAuth-based) are supported, too.
 .
 Load balancing can be implemented either by DNS round-robin mechanism, or with
 the external networking tools, or by
 the built-in ALTERNATE-SERVER mechanism.
 .
 The implementation is intended to be simple to install and configure.
 The project focuses on performance, scalability, and simplicity.
 The aim is to provide an enterprise-grade TURN solution.

coturn-dbgsym: debug symbols for coturn