← Back

CVE-2024-4140

nvd nist
Published: May 2, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: security@ubuntu.com (Secondary)

Description

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

Affected (3)

1 product
Email Mime
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.954
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 39
Version 40

References (24)

Source: security@ubuntu.com
Mailing List
Source: security@ubuntu.com
Issue Tracking
Source: security@ubuntu.com
Issue Tracking
Source: security@ubuntu.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.