VDB

CVE-2024-4140

CVE-2024-4140 PUBLISHED CVSS 7.5 HIGH

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

EPSS 0.28% · 52.0th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.28%
52.0th percentile

Affected Products

VendorProductVersions
rjbsEmail-MIME0
fedoraprojectfedora39, 40
rjbsemail_mime0
rjbsemail-mime0

Timeline

  • Jan 20, 1970 Fix PR Merged
  • May 2, 2024 CVE Published
  • May 3, 2024 EPSS Score
  • May 27, 2024 EPSS Score
  • Jun 21, 2024 EPSS Score
  • Aug 8, 2024 EPSS Score
  • Sep 2, 2024 EPSS Score
  • Sep 26, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 20, 2024 EPSS Score
  • Dec 9, 2024 EPSS Score
  • Jan 2, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›