[SECURITY] Fedora 40 Update: perl-Email-MIME-1.954-1.fc40

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-032e16360b
2024-05-25 01:04:07.908630
--------------------------------------------------------------------------------

Name        : perl-Email-MIME
Product     : Fedora 40
Version     : 1.954
Release     : 1.fc40
URL         : https://metacpan.org/release/Email-MIME
Summary     : Easy MIME message parsing
Description :
This is an extension of the Email::Simple module, to handle MIME
encoded messages. It takes a message as a string, splits it up
into its constituent parts, and allows you access to various
parts of the message. Headers are decoded from MIME encoding.

--------------------------------------------------------------------------------
Update Information:

This update, to the latest upstream release, addresses an excessive memory use
issue (CVE-2024-4140), which can cause denial of service when parsing multi-part
MIME messages; the fix is the new $MAX_PARTS configuration, which limits how
many parts will be considered for parsing, defaulting to 100.
--------------------------------------------------------------------------------
ChangeLog:

* Thu May 16 2024 Paul Howarth <paul@xxxxxxxxxxxx> - 1.954-1
- Update to 1.954 (rhbz#2280644)
  - Fix for CVE-2024-4140: An excessive memory use issue (CWE-770) exists in
    Email-MIME before version 1.954, which can cause denial of service when
    parsing multipart MIME messages; the fix is the new $MAX_PARTS
    configuration, which limits how many parts we will consider parsing
    (the default $MAX_PARTS is 100)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2280644 - Upgrade perl-Email-MIME to 1.954
        https://bugzilla.redhat.com/show_bug.cgi?id=2280644
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-032e16360b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--
_______________________________________________
package-announce mailing list -- package-announce@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to package-announce-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue




[Index of Archives]     [Fedora Users]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [Yosemite Photos]     [KDE Users]

  Powered by Linux