{"id":"MGASA-2024-0198","summary":"Updated perl-Email-MIME packages fix security vulnerabilities","details":"An excessive memory use issue (CWE-770) exists in Email-MIME, before\nversion 1.954, which can cause denial of service when parsing multipart\nMIME messages. The patch set (from 2020 and 2024) limits excessive depth\nand the total number of parts. (CVE-2024-4140)\n","modified":"2026-04-16T04:42:59.177954637Z","published":"2024-05-29T18:08:09Z","upstream":["CVE-2024-4140"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0198.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33248"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFD5BWGYAVLW6IO4SUNLTJCFFLHZYQGT/"}],"affected":[{"package":{"name":"perl-Email-MIME","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/perl-Email-MIME?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.954.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0198.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}