Description

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

INFO

Published Date :

2024-05-02T19:59:20.917Z

Last Modified :

2025-02-13T17:53:29.909Z

Source :

canonical
AFFECTED PRODUCTS

The following products are affected by CVE-2024-4140 vulnerability.

Vendors Products
Fedoraproject
  • Fedora
Rjbs
  • Email-mime

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact