--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-032e16360b
2024-05-25 01:04:07.908630
--------------------------------------------------------------------------------

Name        : perl-Email-MIME
Product     : Fedora 40
Version     : 1.954
Release     : 1.fc40
URL         : https://metacpan.org/release/Email-MIME
Summary     : Easy MIME message parsing
Description :
This is an extension of the Email::Simple module, to handle MIME
encoded messages. It takes a message as a string, splits it up
into its constituent parts, and allows you access to various
parts of the message. Headers are decoded from MIME encoding.

--------------------------------------------------------------------------------
Update Information:

This update, to the latest upstream release, addresses an excessive memory use
issue (CVE-2024-4140), which can cause denial of service when parsing multi-part
MIME messages; the fix is the new $MAX_PARTS configuration, which limits how
many parts will be considered for parsing, defaulting to 100.
--------------------------------------------------------------------------------
ChangeLog:

* Thu May 16 2024 Paul Howarth  - 1.954-1
- Update to 1.954 (rhbz#2280644)
  - Fix for CVE-2024-4140: An excessive memory use issue (CWE-770) exists in
    Email-MIME before version 1.954, which can cause denial of service when
    parsing multipart MIME messages; the fix is the new $MAX_PARTS
    configuration, which limits how many parts we will consider parsing
    (the default $MAX_PARTS is 100)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2280644 - Upgrade perl-Email-MIME to 1.954
        https://bugzilla.redhat.com/show_bug.cgi?id=2280644
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-032e16360b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

Fedora 40: perl-Email-MIME 2024-032e16360b Security Advisory Updates

May 25, 2024
This update, to the latest upstream release, addresses an excessive memory use issue (CVE-2024-4140), which can cause denial of service when parsing multi-part MIME messages; the f...

Summary

This is an extension of the Email::Simple module, to handle MIME

encoded messages. It takes a message as a string, splits it up

into its constituent parts, and allows you access to various

parts of the message. Headers are decoded from MIME encoding.

Update Information:

This update, to the latest upstream release, addresses an excessive memory use issue (CVE-2024-4140), which can cause denial of service when parsing multi-part MIME messages; the fix is the new $MAX_PARTS configuration, which limits how many parts will be considered for parsing, defaulting to 100.

Change Log

* Thu May 16 2024 Paul Howarth - 1.954-1 - Update to 1.954 (rhbz#2280644) - Fix for CVE-2024-4140: An excessive memory use issue (CWE-770) exists in Email-MIME before version 1.954, which can cause denial of service when parsing multipart MIME messages; the fix is the new $MAX_PARTS configuration, which limits how many parts we will consider parsing (the default $MAX_PARTS is 100)

References

[ 1 ] Bug #2280644 - Upgrade perl-Email-MIME to 1.954 https://bugzilla.redhat.com/show_bug.cgi?id=2280644

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-032e16360b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
Name : perl-Email-MIME
Product : Fedora 40
Version : 1.954
Release : 1.fc40
URL : https://metacpan.org/release/Email-MIME
Summary : Easy MIME message parsing

Related News