cbcvebase.
CVE-2004-2771
published 2014-12-24

CVE-2004-2771: The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

Affected

11 ranges
VendorProductVersion rangeFixed in
bsd_mailx_projectbsd_mailx<= 8.1.2
debianbsd-mailx< bsd-mailx 8.1.2-0.20071201cvs-1 (bookworm)bsd-mailx 8.1.2-0.20071201cvs-1 (bookworm)
heirloommailx<= 12.5
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
oraclelinux
oraclelinux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH