CVE-2020-6061
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-6061 is a heap out-of-bounds read vulnerability discovered in CoTURN version 4.5.1.1, disclosed on February 19, 2020. The vulnerability exists in the way the CoTURN web server parses POST requests. CoTURN is a TURN (Traversal Using Relays around NAT) server implementation used as a VoIP media traffic NAT traversal server and gateway (Talos Report).

Technical details

The vulnerability occurs during POST request body parsing where the code responsible for parsing contains a bug leading to out-of-bounds memory access. When preparing to parse the POST request body, while newline and carriage return characters are skipped to get to the start of POST data, the data pointer is incremented but the data_len isn't decremented. This results in bytes beyond the end of the original data buffer being accessed during the subsequent memcpy operation. The vulnerability has a CVSS v3 score of 7.0 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H) (Talos Report).

Impact

The vulnerability can lead to information leaks and other misbehavior. Depending on the memory layout, this could potentially result in further memory corruption, access to sensitive information from other requests, and other unforeseen consequences (Talos Report, Debian Advisory).

Mitigation and workarounds

The vulnerability has been patched in multiple distributions: Ubuntu 20.04 LTS (4.5.1.1-1.1ubuntu0.20.04.1), Ubuntu 19.10 (4.5.1.1-1.1ubuntu0.19.10.1), Ubuntu 18.04 LTS (4.5.0.7-1ubuntu2.18.04.2), Ubuntu 16.04 LTS (4.5.0.3-1ubuntu0.3), Debian stretch (4.5.0.5-1+deb9u2), and Debian buster (4.5.1.1-1.1+deb10u1). Users are recommended to upgrade their coturn packages to these patched versions (Ubuntu Notice, Debian Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management