Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-68553

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine call sites in src/apps/relay/ns_ioalib_engine_impl.c. send_message_to_redis() in src/apps/relay/hiredis_libevent2.c then passes the attacker-controlled key as the format argument to redisAsyncCommand() while supplying only one variadic value, causing hiredis redisvFormatCommand() to read past the va_list. Exploitation can crash the coturn process and terminate active TURN sessions or disclose stack memory into Redis. This issue is fixed in version 4.13.0.

A flaw was found in Coturn. An authenticated TURN user can exploit a format string vulnerability by injecting printf-style format specifiers into the STUN USERNAME or REALM attribute. This can lead to a crash of the coturn process, resulting in a Denial of Service (DoS) and termination of active TURN sessions. Additionally, this vulnerability may disclose sensitive stack memory into Redis.

Отчет

Coturn is not shipped in any Red Hat product. The Fedora and EPEL community builds ship coturn version 4.17.2, which already includes the fix for this issue (fixed in 4.13.0) and are therefore not affected.

Меры по смягчению последствий

Upgrade to coturn version 4.13.0 or later.

Дополнительная информация

Статус:

Important
Дефект:
CWE-134
https://bugzilla.redhat.com/show_bug.cgi?id=2520746coturn: Coturn: Format string vulnerability leads to denial of service and information disclosure

EPSS

Процентиль: 20%
0.00279
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
11 дней назад

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine call sites in src/apps/relay/ns_ioalib_engine_impl.c. send_message_to_redis() in src/apps/relay/hiredis_libevent2.c then passes the attacker-controlled key as the format argument to redisAsyncCommand() while supplying only one variadic value, causing hiredis redisvFormatCommand() to read past the va_list. Exploitation can crash the coturn process and terminate active TURN sessions or disclose stack memory into Redis. This issue is fixed in version 4.13.0.

CVSS3: 7.1
nvd
12 дней назад

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine call sites in src/apps/relay/ns_ioalib_engine_impl.c. send_message_to_redis() in src/apps/relay/hiredis_libevent2.c then passes the attacker-controlled key as the format argument to redisAsyncCommand() while supplying only one variadic value, causing hiredis redisvFormatCommand() to read past the va_list. Exploitation can crash the coturn process and terminate active TURN sessions or disclose stack memory into Redis. This issue is fixed in version 4.13.0.

CVSS3: 7.1
debian
12 дней назад

Coturn is a free open source implementation of TURN and STUN Server. P ...

CVSS3: 7.1
fstec
3 месяца назад

Уязвимость функции send_message_to_redis() файла hiredis_libevent2.c веб-сервера Coturn, позволяющая нарушителю вызвать отказ в обслуживании и раскрыть защищаемую информацию

EPSS

Процентиль: 20%
0.00279
Низкий

7.1 High

CVSS3