{"id":"openSUSE-SU-2020:0937-1","summary":"Security update for coturn","details":"This update for coturn fixes the following issues:\n\nVersion 4.5.1.3:\n\n* Remove reference to SSLv3: gh#coturn/coturn#566\n* Ignore MD5 for BoringSSL: gh#coturn/coturn#579\n* STUN response buffer not initialized properly; he issue found and \n  reported gh#coturn/coturn#583 by Felix D�rre all credits belongs to \n  him. CVE-2020-4067, boo#1173510\n- Let coturn allow binding to ports below 1024 per default\n","modified":"2026-01-30T00:30:20.611808Z","published":"2020-07-06T22:28:40Z","related":["CVE-2020-4067"],"upstream":["CVE-2020-4067"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KSEKBPGO2SMOAK5MFJM27REZGSIHH6QK/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173510"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-4067"}],"affected":[{"package":{"name":"coturn","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/coturn&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.1.3-lp152.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"coturn-devel":"4.5.1.3-lp152.2.3.1","coturn-utils":"4.5.1.3-lp152.2.3.1","coturn":"4.5.1.3-lp152.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0937-1.json"}}],"schema_version":"1.7.3"}