VDB
Sign up
HIGH7.5

GHSA-gmc6-fwg3-75m5

Mimekit has vulnerable dependency that can lead to denial of service

Quick fix

GHSA-gmc6-fwg3-75m5 — MimeKit: upgrade to the fixed version with the command below.

dotnet add package MimeKit --version 4.7.1

Details

### Summary Denial of service vulnerability.

### Details See: https://github.com/advisories/GHSA-447r-wph3-92pm and https://github.com/dotnet/announcements/issues/312

### PoC Update System.Security.Cryptography.Pkcs to 8.0.1 so that the transitive dependency with the issue gets updated

### Impact Denial of service vulnerability. Affects MimeKit (>= v3.0.0 and <= v4.7.0) when used to decrypt or verify incoming S/MIME messages as well as importing 3rd-party X.509 certificates for use with encrypting outgoing S/MIME messages.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/MimeKit
Introduced in: 3.0.0Fixed in: 4.7.1
Fixdotnet add package MimeKit --version 4.7.1

References