An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
References
Configurations
History
26 Aug 2025, 17:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* cpe:2.3:a:rjbs:email-mime:*:*:*:*:*:*:*:* |
|
References | () https://bugs.debian.org/960062 - Mailing List | |
References | () https://github.com/rjbs/Email-MIME/commit/02bf3e26812c8f38a86a33c168571f9783365df2 - Patch | |
References | () https://github.com/rjbs/Email-MIME/commit/3a12edd119e493156a5a05e45dd50f4e36b702e8 - Patch | |
References | () https://github.com/rjbs/Email-MIME/commit/3dcf096eeccb8e4dd42738de676c8f4a5aa7a531 - Patch | |
References | () https://github.com/rjbs/Email-MIME/commit/7e96ecfa1da44914a407f82ae98ba817bba08f2d - Patch | |
References | () https://github.com/rjbs/Email-MIME/commit/b2cb62f19e12580dd235f79e2546d44a6bec54d1 - Patch | |
References | () https://github.com/rjbs/Email-MIME/commit/fc0fededd24a71ccc51bcd8b1e486385d09aae63 - Patch | |
References | () https://github.com/rjbs/Email-MIME/issues/66 - Issue Tracking | |
References | () https://github.com/rjbs/Email-MIME/pull/80 - Issue Tracking | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFD5BWGYAVLW6IO4SUNLTJCFFLHZYQGT/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YHXHDLPZ6JV4KK3Q43O6TE3WOBAIUQRC/ - Mailing List | |
References | () https://www.cve.org/CVERecord?id=CVE-2024-4140 - Third Party Advisory | |
First Time |
Rjbs
Fedoraproject Rjbs email-mime Fedoraproject fedora |
Information
Published : 2024-05-02 20:15
Updated : 2025-08-26 17:21
NVD link : CVE-2024-4140
Mitre link : CVE-2024-4140
CVE.ORG link : CVE-2024-4140
JSON object : View
Products Affected
rjbs
- email-mime
fedoraproject
- fedora
CWE
CWE-770
Allocation of Resources Without Limits or Throttling