CVE-2010-0009

NameCVE-2010-0009
DescriptionApache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs576304

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
couchdbsource(unstable)0.11.0-1576304

Notes

[lenny] - couchdb <no-dsa> (Minor information leak)

Search for package or bug name: Reporting problems