Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-21016

Use constant time comparison for SCRAM1 signature comparisons

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major - P3
    • Resolution: Fixed
    • Affects Version/s: 3.0.7, 3.2.0-rc0
    • Fix Version/s: 3.2.0-rc3
    • Component/s: Internal Client
    • Labels:
      None
    • Backwards Compatibility:
      Fully Compatible
    • Operating System:
      ALL
    • Sprint:
      Platform B (10/30/15), Platform C (11/20/15)

      Description

      Per DRIVERS-255, client implementations of SCRAM should use constant-time memory comparisons to verify the hash.

        Attachments

          Activity

            People

            Assignee:
            mark.benvenuto Mark Benvenuto
            Reporter:
            mark.benvenuto Mark Benvenuto
            Participants:
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: