An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
References
Configurations
No configuration.
History
21 Nov 2024, 09:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.debian.org/960062 - | |
References | () https://github.com/rjbs/Email-MIME/commit/02bf3e26812c8f38a86a33c168571f9783365df2 - | |
References | () https://github.com/rjbs/Email-MIME/commit/3a12edd119e493156a5a05e45dd50f4e36b702e8 - | |
References | () https://github.com/rjbs/Email-MIME/commit/3dcf096eeccb8e4dd42738de676c8f4a5aa7a531 - | |
References | () https://github.com/rjbs/Email-MIME/commit/7e96ecfa1da44914a407f82ae98ba817bba08f2d - | |
References | () https://github.com/rjbs/Email-MIME/commit/b2cb62f19e12580dd235f79e2546d44a6bec54d1 - | |
References | () https://github.com/rjbs/Email-MIME/commit/fc0fededd24a71ccc51bcd8b1e486385d09aae63 - | |
References | () https://github.com/rjbs/Email-MIME/issues/66 - | |
References | () https://github.com/rjbs/Email-MIME/pull/80 - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFD5BWGYAVLW6IO4SUNLTJCFFLHZYQGT/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YHXHDLPZ6JV4KK3Q43O6TE3WOBAIUQRC/ - | |
References | () https://www.cve.org/CVERecord?id=CVE-2024-4140 - |
10 Jun 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 May 2024, 12:50
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
02 May 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 May 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-02 20:15
Updated : 2024-11-21 09:42
NVD link : CVE-2024-4140
Mitre link : CVE-2024-4140
CVE.ORG link : CVE-2024-4140
JSON object : View
Products Affected
No product.
CWE
CWE-770
Allocation of Resources Without Limits or Throttling