CVE-2017-5361: Medium severity request tracker vulnerability
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5361?
CVE-2017-5361 has a medium severity due to its potential to expose sensitive user passwords through timing attacks.
How do I fix CVE-2017-5361?
The recommended fix for CVE-2017-5361 is to upgrade Request Tracker to version 4.0.25, 4.2.14, or 4.4.2 or later.
What versions are affected by CVE-2017-5361?
CVE-2017-5361 affects Request Tracker versions 4.0.x prior to 4.0.25, 4.2.x prior to 4.2.14, and 4.4.x prior to 4.4.2.
What type of attack does CVE-2017-5361 enable?
CVE-2017-5361 enables remote attackers to exploit timing side-channel vulnerabilities to obtain sensitive information.
Is CVE-2017-5361 a local or remote vulnerability?
CVE-2017-5361 is a remote vulnerability, allowing attackers to exploit it without direct access to the server.