functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preferences files.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-08-19 11:00
Updated : 2017-08-16 18:32
NVD link : CVE-2010-2813
Mitre link : CVE-2010-2813
JSON object : View
CWE
CWE-399
Resource Management Errors
Products Affected
squirrelmail
- squirrelmail