From 060bf187879fd1a6386012f4c5a7494824ebe5c8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?M=C3=A9sz=C3=A1ros=20Mih=C3=A1ly?= Date: Sun, 10 Jan 2021 10:25:19 +0100 Subject: [PATCH] Changelog for CVE-2020-26262 --- ChangeLog | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/ChangeLog b/ChangeLog index 8cf6e2b..7770318 100644 --- a/ChangeLog +++ b/ChangeLog @@ -45,6 +45,11 @@ Version 4.5.2 'dan Eider': * Simplify (as agreed in Issue #666) * Remove session id/allocation labels * Remove per session metrics. We should later add more counters. + - Fix CVE-2020-26262 (credits: Enable-Security) + * Fix ipv6 ::1 loopback check + * Not allow allocate peer address 0.0.0.0/8 and ::/128 + * For more details see the github security advisory: + https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p 24/06/2020 Oleg Moskalenko Mihály Mészáros Version 4.5.1.3 'dan Eider':