Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10835
HistoryJan 15, 2019 - 8:52 a.m.

Denial Of Service

2019-01-1508:52:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.115

Percentile

95.3%

SquirrelMail is vulnerable to denial of service attack.For log in attempts with 8-bit character passwords, the library creates user preference file even if the user name is invalid. Using this flaw, an attacker can exhaust memory in server by making many invalid IMAP log in attempts with different user names, leading to denial of service. The vulnerability is a result of incorrect fix for CVE-2010-2813.