CVE-2010-0009: Infoleak

Published Mar 31, 2010
·
Updated

Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.

Other sources

Apache CouchDB upstream has released latest, v0.11.0 version, addressing timing attack flaw(s). More from Bugtraq post: [1] http://seclists.org/bugtraq/2010/Mar/254

"Apache CouchDB versions prior to version 0.11.0 are vulnerable to timing attacks, also known as side-channel information leakage, due to using simple break-on-inequality string comparisons when verifying hashes and passwords."

References: [2] http://wiki.apache.org/couchdb/Breakingchanges [3] http://codahale.com/a-lesson-in-timing-attacks/ [4] http://couchdb.apache.org/ [5] http://couchdb.apache.org/downloads.html

Credit: Jason Davies of the Apache CouchDB development team

CVE Request for Apache CouchDB v0.11.0: [6] http://www.openwall.com/lists/oss-security/2010/03/31/5

Red Hat

Affected Software

7 affected components
Apache CouchDB=0.9.0
Apache CouchDB=0.9.1
Apache CouchDB=0.8.1
Apache CouchDB=0.10.1
Apache CouchDB=0.9.2
Apache CouchDB=0.10.0
Apache CouchDB=0.8.0

Remediation

Event History

Mar 31, 2010
Data Sourced
via Red Hat·05:04 PM
DescriptionSeverityAffected Software
Apr 5, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-0009?

CVE-2010-0009 is classified as a medium severity vulnerability due to its potential for data exposure via timing attacks.

2

How do I fix CVE-2010-0009?

To mitigate CVE-2010-0009, upgrade to Apache CouchDB version 0.11.0 or later which addresses the timing attack flaw.

3

What versions of Apache CouchDB are affected by CVE-2010-0009?

CVE-2010-0009 affects Apache CouchDB versions 0.8.0 through 0.10.1.

4

Can CVE-2010-0009 lead to sensitive data exposure?

Yes, CVE-2010-0009 can allow remote attackers to glean sensitive information by analyzing the completion timing of certain operations.

5

Is there a patch available for CVE-2010-0009?

Yes, the latest version 0.11.0 of Apache CouchDB includes a patch for the vulnerabilities described in CVE-2010-0009.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203