CVE-2012-2124: Medium severity squirrelmail vulnerability
A Red Hat Security Advisory RHSA-2012:0103 for squirrelmail packages shipped in Red Hat Enterprise Linux 4 and 5 claim to have fixed CVE-2010-2813 issue ("CVE-2010-2813 SquirrelMail: DoS (disk space consumption) by random IMAP login attempts with 8-bit characters in the password", bug #618096). However, the patch for this issue was not applied correctly and hence the issue was not fixed as stated in the advisory.
Other sources
functions/imapgeneral.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files. NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2124?
CVE-2012-2124 is classified as a moderate severity vulnerability affecting SquirrelMail.
What systems are affected by CVE-2012-2124?
CVE-2012-2124 affects SquirrelMail packages on Red Hat Enterprise Linux 4 and 5.
How do I fix CVE-2012-2124?
To fix CVE-2012-2124, update the SquirrelMail package to the latest version available for your Red Hat Enterprise Linux version.
What type of vulnerability is CVE-2012-2124?
CVE-2012-2124 is related to a denial of service (DoS) vulnerability.
Is there a workaround for CVE-2012-2124?
While a specific workaround is not detailed, best practices include limiting access to the SquirrelMail application until the update is applied.