Apache CouchDB < 0.11.0 Hash Verification Information Leak

medium Nessus Plugin ID 45435

Synopsis

The remote database server has an information leak vulnerability.

Description

According to its banner, the version of CouchDB running on the remote host has an information leak vulnerability. The application does not use a constant-time comparison algorithm when attempting to verify hashes and passwords. The server will respond to mismatches more quickly than it responds to matches.

A remote attacker could exploit this by performing side-channel brute force attacks, which could lead to administrative access.

Solution

Upgrade to CouchDB 0.11.0 or later.

See Also

https://seclists.org/bugtraq/2010/Mar/254

Plugin Details

Severity: Medium

ID: 45435

File Name: couchdb_0_11_0.nasl

Version: 1.12

Type: remote

Family: Databases

Published: 4/7/2010

Updated: 11/15/2018

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:apache:couchdb

Required KB Items: Settings/ParanoidReport, www/couchdb

Exploit Ease: No known exploits are available

Patch Publication Date: 3/31/2010

Vulnerability Publication Date: 3/31/2010

Reference Information

CVE: CVE-2010-0009

BID: 39116

Secunia: 39146