Debian Security Advisory
DSA-3883-1 rt-authen-externalauth -- security update
- Date Reported:
- 15 Jun 2017
- Affected Packages:
- rt-authen-externalauth
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-5361.
- More information:
-
It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.
For the stable distribution (jessie), this problem has been fixed in version 0.25-1+deb8u1.
We recommend that you upgrade your rt-authen-externalauth packages.