Description
functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preferences files.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2091-1 | New squirrelmail packages fix cross-site request forgery |
EUVD |
EUVD-2010-2817 | functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preferences files. |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T02:46:48.556Z
Reserved: 2010-07-22T00:00:00.000Z
Link: CVE-2010-2813
No data.
Status : Deferred
Published: 2010-08-19T18:00:05.657
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-2813
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD