Vulnerable Systems:
* Apache CouchDB 0.8.0 to 0.10.1
Immune Systems:
* Apache CouchDB 0.11.0
Apache CouchDB versions prior to version 0.11.0 are vulnerable to timing attacks, also known as side-channel information leakage, due to using simple break-on-inequality string comparisons when verifying hashes and passwords.
Patch Availability:
All users should upgrade to CouchDB 0.11.0. Upgrades from the 0.10.x series should be seamless. Users on earlier versions should consult: http://wiki.apache.org/couchdb/Breaking_changes