Vulnerability Description
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rjbs | Email-Mime | < 1.954 |
| Fedoraproject | Fedora | 39 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/960062Mailing List
- https://github.com/rjbs/Email-MIME/commit/02bf3e26812c8f38a86a33c168571f9783365dPatch
- https://github.com/rjbs/Email-MIME/commit/3a12edd119e493156a5a05e45dd50f4e36b702Patch
- https://github.com/rjbs/Email-MIME/commit/3dcf096eeccb8e4dd42738de676c8f4a5aa7a5Patch
- https://github.com/rjbs/Email-MIME/commit/7e96ecfa1da44914a407f82ae98ba817bba08fPatch
- https://github.com/rjbs/Email-MIME/commit/b2cb62f19e12580dd235f79e2546d44a6bec54Patch
- https://github.com/rjbs/Email-MIME/commit/fc0fededd24a71ccc51bcd8b1e486385d09aaePatch
- https://github.com/rjbs/Email-MIME/issues/66Issue Tracking
- https://github.com/rjbs/Email-MIME/pull/80Issue Tracking
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://www.cve.org/CVERecord?id=CVE-2024-4140Third Party Advisory
- https://bugs.debian.org/960062Mailing List
- https://github.com/rjbs/Email-MIME/commit/02bf3e26812c8f38a86a33c168571f9783365dPatch
- https://github.com/rjbs/Email-MIME/commit/3a12edd119e493156a5a05e45dd50f4e36b702Patch
FAQ
What is CVE-2024-4140?
CVE-2024-4140 is a vulnerability with a CVSS score of 7.5 (HIGH). An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits ex...
How severe is CVE-2024-4140?
CVE-2024-4140 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4140?
Check the references section above for vendor advisories and patch information. Affected products include: Rjbs Email-Mime, Fedoraproject Fedora.