VDB
CVE-2012-2124
CVE-2012-2124
PUBLISHED
CVSS 5 MEDIUM
functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files. NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.
EPSS 2.45% · 83.1th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.45%
83.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| squirrelmail | squirrelmail | |
| n/a | n/a | n/a |
| redhat | enterprise_linux | 4, 5 |
Timeline
- Jan 18, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 17, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 51730 third-party-advisory
- [oss-security] 20120420 CVE-2012-2124 assignment notification: squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103 mailing-list
- RHSA-2013:0126 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-2124 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=814671 url