atom feed1 message in[SECURITY] CVE-2008-2370: Apache Couc...
FromSent OnAttachments
Jan LehnardtMar 31, 2010 6:54 am 
Subject:[SECURITY] CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability
From:Jan Lehnardt (
Date:Mar 31, 2010 6:54:00 am

My sincere apologies, I mixed up the CVE number. Here is the update report.

Cheers Jan


CVE-2010-0009: Apache CouchDB Timing Attack Vulnerability

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected: Apache CouchDB 0.8.0 to 0.10.1

Description: Apache CouchDB versions prior to version 0.11.0 are vulnerable to timing attacks, also known as side-channel information leakage, due to using simple break-on-inequality string comparisons when verifying hashes and passwords.

Mitigation: All users should upgrade to CouchDB 0.11.0. Upgrades from the 0.10.x series should be seamless. Users on earlier versions should consult

Example: A canonical description of the attack can be found in

Credit: This issue was discovered by Jason Davies of the Apache CouchDB development team.