Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
From: Jan Lehnardt (janapache.org)
Date: Wed Mar 31 2010 - 08:54:00 CDT
My sincere apologies, I mixed up the CVE number. Here is the update report.
CVE-2010-0009: Apache CouchDB Timing Attack Vulnerability
The Apache Software Foundation
Apache CouchDB 0.8.0 to 0.10.1
Apache CouchDB versions prior to version 0.11.0 are vulnerable to
timing attacks, also known as side-channel information leakage,
due to using simple break-on-inequality string comparisons when
verifying hashes and passwords.
All users should upgrade to CouchDB 0.11.0. Upgrades from the 0.10.x
series should be seamless. Users on earlier versions should consult
A canonical description of the attack can be found in
This issue was discovered by Jason Davies of the Apache CouchDB