Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/39116 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=578572 | |
http://www.securityfocus.com/archive/1/510427/100/0/threaded | mailing list |
http://secunia.com/advisories/39146 | third party advisory vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2010-03/0267.html | mailing list |
http://couchdb.apache.org/security.html | patch vendor advisory |
http://www.osvdb.org/63350 | vdb entry |