Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-2124
Description:functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files. NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.
Test IDs: 1.3.6.1.4.1.25623.1.0.123760  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-2124
51730
http://secunia.com/advisories/51730
RHSA-2013:0126
http://rhn.redhat.com/errata/RHSA-2013-0126.html
[oss-security] 20120420 CVE-2012-2124 assignment notification: squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
http://www.openwall.com/lists/oss-security/2012/04/20/22
https://bugzilla.redhat.com/show_bug.cgi?id=814671
https://bugzilla.redhat.com/show_bug.cgi?id=814671




© 1998-2025 E-Soft Inc. All rights reserved.