Home Embedded Vulns General Vulns

CVE-2020-6061

CRITICAL 9.8

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date February 19, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.

Potentially Affected Vendors