Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-2813
HistoryAug 19, 2010 - 12:00 a.m.

CVE-2010-2813

2010-08-1900:00:00
ubuntu.com
ubuntu.com
15

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.115

Percentile

95.3%

functions/imap_general.php in SquirrelMail before 1.4.21 does not properly
handle 8-bit characters in passwords, which allows remote attackers to
cause a denial of service (disk consumption) by making many IMAP login
attempts with different usernames, leading to the creation of many
preferences files.

Bugs

Notes

Author Note
tyhicks Note that Red Hat Security Advisory RHSA-2012:010 was incomplete (see CVE-2012-2124)

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.115

Percentile

95.3%