PT-2010-4308 · Squirrelmail+1 · Squirrelmail+1

Mikhail Goriachev

·

Published

2010-08-19

·

Updated

2017-08-17

·

CVE-2010-2813

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions SquirrelMail versions prior to 1.4.21
Description The issue arises from improper handling of 8-bit characters in passwords by the functions/imap general.php file. This allows remote attackers to cause a denial of service, specifically disk consumption, by making multiple IMAP login attempts with different usernames. As a result, many preferences files are created.
Recommendations For versions prior to 1.4.21, update to version 1.4.21 or later to resolve the issue. As a temporary workaround, consider restricting the number of IMAP login attempts to minimize the risk of disk consumption.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2813
DSA-2091-1
RHSA-2012:0103
RHSA-2012_0103

Affected Products

Red Hat
Squirrelmail