CVE-2004-2771
published 2014-12-24CVE-2004-2771: The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell…
PriorityP354high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.86%
93.3th percentile
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bsd_mailx_project | bsd_mailx | <= 8.1.2 | — |
| debian | bsd-mailx | < bsd-mailx 8.1.2-0.20071201cvs-1 (bookworm) | bsd-mailx 8.1.2-0.20071201cvs-1 (bookworm) |
| heirloom | mailx | <= 12.5 | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2004-2771: NIST NVD Details: https://nvd
vendor_msrc·2024-06-11·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2004-2771
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Remediation: mailx
Reference: https://nvd.nist.gov/vuln/detail/CVE-2004-2771
Red Hat
mailx: command execution flaw
vendor_redhat·2014-12-16·CVSS 7.5
CVE-2014-7844 [HIGH] CWE-78 mailx: command execution flaw
mailx: command execution flaw
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
A flaw was found in the way mailx handled the parsing of email addresses. A syntactically valid email address could allow a local attacker to cause mailx to execute arbitrary shell commands through shell meta-characters (CVE-2004-2771) and the direct command execution functionality (CVE-2014-7844).
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/
Red Hat
mailx: command execution flaw
vendor_redhat·2014-12-16·CVSS 7.5
CVE-2004-2771 [HIGH] CWE-78 mailx: command execution flaw
mailx: command execution flaw
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
A flaw was found in the way mailx handled the parsing of email addresses. A syntactically valid email address could allow a local attacker to cause mailx to execute arbitrary shell commands through shell meta-characters (CVE-2004-2771) and the direct command execution functionality (CVE-2014-7844).
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the R
Debian
CVE-2004-2771: bsd-mailx - The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8....
vendor_debian·2004·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771: bsd-mailx - The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8....
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
Scope: local
bookworm: resolved (fixed in 8.1.2-0.20071201cvs-1)
bullseye: resolved (fixed in 8.1.2-0.20071201cvs-1)
forky: resolved (fixed in 8.1.2-0.20071201cvs-1)
sid: resolved (fixed in 8.1.2-0.20071201cvs-1)
trixie: resolved (fixed in 8.1.2-0.20071201cvs-1)
GHSA
GHSA-3f68-9fxg-g2j6: The expand function in fio
ghsa_unreviewed·2022-04-29
CVE-2004-2771 [HIGH] CWE-20 GHSA-3f68-9fxg-g2j6: The expand function in fio
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
OSV
CVE-2004-2771: The expand function in fio
osv·2014-12-24·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771: The expand function in fio
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
bugzilla·2014-12-17·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for nail: see blocks bug list for fu
Bugzilla
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw [fedora-all]
bugzilla·2014-12-16·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw [fedora-all]
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2004-2771 CVE-2014-7844 bsd-mailx: mailx: command execution flaw [epel-6]
bugzilla·2014-12-16·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 bsd-mailx: mailx: command execution flaw [epel-6]
CVE-2004-2771 CVE-2014-7844 bsd-mailx: mailx: command execution flaw [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for bsd-mailx: see blocks bug l
Bugzilla
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
bugzilla·2014-11-11·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
Florian Weimer from Red Hat has reported the below issue:
mailx executes shell commands embedded in syntactically valid mail addresses due a not quoted command to prevent word expansion.
fio.c
542 }
543 snprintf(cmdbuf, sizeof cmdbuf, "echo %s", name);
544 if ((shell = value("SHELL")) == NULL)
545 shell = SHELL;
The original report in Debian bugtracker:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748
Discussion:
Created attachment 958222
0001-outof-Introduce-expandaddr-flag.patch
---
Created attachment 958223
0002-unpack-Disable-option-processing-for-email-addresses.patch
---
Created attachment 958224
0003-fio.c-Unconditionally-require-wordexp-support.patch
---
Created attachment 958225
0004-globname-Invoke-wor
http://linux.oracle.com/errata/ELSA-2014-1999.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1999.htmlhttp://seclists.org/oss-sec/2014/q4/1066http://secunia.com/advisories/60940http://secunia.com/advisories/61585http://secunia.com/advisories/61693http://www.debian.org/security/2014/dsa-3105https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748http://linux.oracle.com/errata/ELSA-2014-1999.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1999.htmlhttp://seclists.org/oss-sec/2014/q4/1066http://secunia.com/advisories/60940http://secunia.com/advisories/61585http://secunia.com/advisories/61693http://www.debian.org/security/2014/dsa-3105https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748
2014-12-24
Published