LWN.net Logo

squirrelmail: denial of service

Package(s):squirrelmail CVE #(s):CVE-2012-2124
Created:January 17, 2013 Updated:January 23, 2013
Description:

From the Red Hat advisory:

The SquirrelMail security update RHSA-2012:0103 did not, unlike the erratum text stated, correct the CVE-2010-2813 issue, a flaw in the way SquirrelMail handled failed log in attempts. A user preference file was created when attempting to log in with a password containing an 8-bit character, even if the username was not valid. A remote attacker could use this flaw to eventually consume all hard disk space on the target SquirrelMail server. (CVE-2012-2124)

Alerts:
Scientific Linux SL-squi-20130116 2013-01-16
CentOS CESA-2013:0130 2013-01-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds