Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

[SECURITY] CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability
From: Jan Lehnardt <jan () apache org>
Date: Wed, 31 Mar 2010 15:48:01 +0200

CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability

Severity: Important

Vendor:
The Apache Software Foundation

Versions Affected:
Apache CouchDB 0.8.0 to 0.10.1

Description:
Apache CouchDB versions prior to version 0.11.0 are vulnerable to
timing attacks, also known as side-channel information leakage,
due to using simple break-on-inequality string comparisons when
verifying hashes and passwords.

Mitigation:
All users should upgrade to CouchDB 0.11.0. Upgrades from the 0.10.x
series should be seamless. Users on earlier versions should consult

 http://wiki.apache.org/couchdb/Breaking_changes

Example:
A canonical description of the attack can be found in

 http://codahale.com/a-lesson-in-timing-attacks/

Credit:
This issue was discovered by Jason Davies of the Apache CouchDB 
development team.

References:
http://couchdb.apache.org/
http://couchdb.apache.org/downloads.html
http://wiki.apache.org/couchdb/Breaking_changes
http://codahale.com/a-lesson-in-timing-attacks/

Jan Lehnardt
--

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault