functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preferences files.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Addressbook | — | Upgrade macOS to the latest versionApply OS X security update 2012-001 | Aug 28, 2015 | Aug 19, 2010 |
| Apple Osx Squirrelmail | — | Apply OS X security update 2012-001 | Feb 3, 2012 | Aug 19, 2010 |
| Centos_linux | — | Upgrade squirrelmail | Dec 1, 2016 | Aug 19, 2010 |
| Oracle_linux | — | Upgrade squirrelmail | Oct 16, 2024 | Aug 19, 2010 |
| Redhat_linux | — | — | Jul 9, 2025 | Jul 23, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub