Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack.
{
"binaries": [
{
"binary_version": "4.2.12-5",
"binary_name": "request-tracker4"
},
{
"binary_version": "4.2.12-5",
"binary_name": "rt4-apache2"
},
{
"binary_version": "4.2.12-5",
"binary_name": "rt4-clients"
},
{
"binary_version": "4.2.12-5",
"binary_name": "rt4-db-mysql"
},
{
"binary_version": "4.2.12-5",
"binary_name": "rt4-db-postgresql"
},
{
"binary_version": "4.2.12-5",
"binary_name": "rt4-db-sqlite"
},
{
"binary_version": "4.2.12-5",
"binary_name": "rt4-doc-html"
},
{
"binary_version": "4.2.12-5",
"binary_name": "rt4-fcgi"
},
{
"binary_version": "4.2.12-5",
"binary_name": "rt4-standalone"
}
]
}