An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
History

Tue, 26 Aug 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
Rjbs
Rjbs email-mime
CPEs cpe:2.3:a:rjbs:email-mime:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora
Rjbs
Rjbs email-mime

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published: 2024-05-02T19:59:20.917Z

Updated: 2025-02-13T17:53:29.909Z

Reserved: 2024-04-24T17:32:29.243Z

Link: CVE-2024-4140

cve-icon Vulnrichment

Updated: 2024-08-01T20:33:52.936Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-02T20:15:07.333

Modified: 2025-08-26T17:21:28.577

Link: CVE-2024-4140

cve-icon Redhat

No data.