MGASA-2021-0078 - Updated perl-Email-MIME and perl-Email-MIME-ContentType packages fix security vulnerability

Publication date: 10 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0078.html
Type: security
Affected Mageia releases: 7

Messages with too many tiny nested MIME parts can lead to memory exhaustion on
split(), resulting in denial of service (rhbz#1835353)

This update limits the number of nested MIME parts to 10 (by default), to avoid
a possible memory exhaustion issue with lots of tiny MIME parts.

References:
- https://bugs.mageia.org/show_bug.cgi?id=26757
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VJFUIVJOQGZOYF4Q4RXPBJTBBZD5LXVK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3PWODHVD5ZKQBY2OYBTFPBETUOOJA33D/

SRPMS:
- 7/core/perl-Email-MIME-1.949.0-3.1.mga7
- 7/core/perl-Email-MIME-ContentType-1.24.0-3.1.mga7

Mageia 2021-0078: perl-Email-MIME and perl-Email-MIME-ContentType security update

Messages with too many tiny nested MIME parts can lead to memory exhaustion on split(), resulting in denial of service (rhbz#1835353) This update limits the number of nested MIME ...

Summary

Messages with too many tiny nested MIME parts can lead to memory exhaustion on split(), resulting in denial of service (rhbz#1835353) This update limits the number of nested MIME parts to 10 (by default), to avoid a possible memory exhaustion issue with lots of tiny MIME parts.

References

- https://bugs.mageia.org/show_bug.cgi?id=26757

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VJFUIVJOQGZOYF4Q4RXPBJTBBZD5LXVK/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3PWODHVD5ZKQBY2OYBTFPBETUOOJA33D/

Resolution

MGASA-2021-0078 - Updated perl-Email-MIME and perl-Email-MIME-ContentType packages fix security vulnerability

SRPMS

- 7/core/perl-Email-MIME-1.949.0-3.1.mga7

- 7/core/perl-Email-MIME-ContentType-1.24.0-3.1.mga7

Severity
Publication date: 10 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0078.html
Type: security

Related News