https://bugzilla.redhat.com/show_bug.cgi?id=1835353 Bug ID: 1835353 Summary: rubygem-mail: Out of memory issue through nested MIME parts Product: Security Response Hardware: All OS: Linux Status: NEW Component: vulnerability Keywords: Security Severity: medium Priority: medium Assignee: security-response-team@xxxxxxxxxx Reporter: psampaio@xxxxxxxxxx CC: akarol@xxxxxxxxxx, alexl@xxxxxxxxxx, bbuckingham@xxxxxxxxxx, bcourt@xxxxxxxxxx, bkearney@xxxxxxxxxx, btotty@xxxxxxxxxx, caillon+fedoraproject@xxxxxxxxx, caolanm@xxxxxxxxxx, dmetzger@xxxxxxxxxx, gmccullo@xxxxxxxxxx, gnome-sig@xxxxxxxxxxxxxxxxxxxxxxx, gtanzill@xxxxxxxxxx, hhudgeon@xxxxxxxxxx, jfrey@xxxxxxxxxx, jhardy@xxxxxxxxxx, john.j5live@xxxxxxxxx, jose.p.oliveira.oss@xxxxxxxxx, lzap@xxxxxxxxxx, mclasen@xxxxxxxxxx, mmccune@xxxxxxxxxx, nmoumoul@xxxxxxxxxx, obarenbo@xxxxxxxxxx, paul@xxxxxxxxxxxx, perl-devel@xxxxxxxxxxxxxxxxxxxxxxx, rchan@xxxxxxxxxx, rhughes@xxxxxxxxxx, rjerrido@xxxxxxxxxx, rob.myers@xxxxxxxxxxxxxxx, roliveri@xxxxxxxxxx, rstrode@xxxxxxxxxx, sandmann@xxxxxxxxxx, simaishi@xxxxxxxxxx, smallamp@xxxxxxxxxx, sokeeffe@xxxxxxxxxx, tbrisker@xxxxxxxxxx, tcallawa@xxxxxxxxxx, vondruch@xxxxxxxxxx, walter.pete@xxxxxxxxxx, xavier@xxxxxxxxxxxx Target Milestone: --- Classification: Other A possible DoS issue may affect several MIME parsers. Messages with too many tiny nested MIME parts can lead to memory exhaustion on split(). References: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960064 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960062 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960159 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960158 -- You are receiving this mail because: You are on the CC list for the bug. _______________________________________________ perl-devel mailing list -- perl-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to perl-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/perl-devel@xxxxxxxxxxxxxxxxxxxxxxx