It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable. For the stable distribution (jessie), this problem has been fixed in version 0.25-1+deb8u1. We recommend that you upgrade your rt-authen-externalauth packages.
It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.
For the stable distribution (jessie), this problem has been fixed in version 0.25-1+deb8u1.
We recommend that you upgrade your rt-authen-externalauth packages.