|
|
| |
|
| |
squirrelmail: denial of service
| Package(s): | squirrelmail |
CVE #(s): | CVE-2012-2124
|
| Created: | January 17, 2013 |
Updated: | January 23, 2013 |
| Description: |
From the Red Hat advisory:
The SquirrelMail security update RHSA-2012:0103 did not, unlike the erratum
text stated, correct the CVE-2010-2813 issue, a flaw in the way
SquirrelMail handled failed log in attempts. A user preference file was
created when attempting to log in with a password containing an 8-bit
character, even if the username was not valid. A remote attacker could use
this flaw to eventually consume all hard disk space on the target
SquirrelMail server. (CVE-2012-2124) |
| Alerts: |
|
( Log in to post comments)
|
|
|