CVE-2014-7844
published 2020-01-14CVE-2014-7844: BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.55%
72.3th percentile
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| bsd | mailx | — | — |
| bsd_mailx_project | bsd_mailx | — | — |
| debian | bsd-mailx | < bsd-mailx 8.1.2-0.20141216cvs-1 (bookworm) | bsd-mailx 8.1.2-0.20141216cvs-1 (bookworm) |
| debian | debian_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v8v3-2m82-gr7p: BSD mailx 8
ghsa_unreviewed·2022-05-17
CVE-2014-7844 [HIGH] CWE-74 GHSA-v8v3-2m82-gr7p: BSD mailx 8
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
OSV
CVE-2014-7844: BSD mailx 8
osv·2020-01-14·CVSS 7.8
CVE-2014-7844 [HIGH] CVE-2014-7844: BSD mailx 8
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
Ubuntu
bsd-mailx vulnerability
vendor_ubuntu·2015-01-07
CVE-2014-7844 bsd-mailx vulnerability
Title: bsd-mailx vulnerability
Summary: bsd-mailx could be made to run programs if it parsed a specially crafted
email address.
It was discovered that bsd-mailx contained a feature that allowed
syntactically valid email addresses to be treated as shell commands. A
remote attacker could possibly use this issue with a valid email address to
execute arbitrary commands.
This functionality has now been disabled by default, and can be re-enabled
with the "expandaddr" configuration option. This update alone does not
remove all possibilities of command execution. In environments where
scripts use mailx to process arbitrary email addresses, it is recommended
to modify them to use a "--" separator before the address to properly
handle those that begin with "-". In addition, specifying sendmail op
Red Hat
mailx: command execution flaw
vendor_redhat·2014-12-16·CVSS 7.5
CVE-2014-7844 [HIGH] CWE-78 mailx: command execution flaw
mailx: command execution flaw
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
A flaw was found in the way mailx handled the parsing of email addresses. A syntactically valid email address could allow a local attacker to cause mailx to execute arbitrary shell commands through shell meta-characters (CVE-2004-2771) and the direct command execution functionality (CVE-2014-7844).
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/
Red Hat
mailx: command execution flaw
vendor_redhat·2014-12-16·CVSS 7.5
CVE-2004-2771 [HIGH] CWE-78 mailx: command execution flaw
mailx: command execution flaw
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
A flaw was found in the way mailx handled the parsing of email addresses. A syntactically valid email address could allow a local attacker to cause mailx to execute arbitrary shell commands through shell meta-characters (CVE-2004-2771) and the direct command execution functionality (CVE-2014-7844).
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the R
Debian
CVE-2014-7844: bsd-mailx - BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary command...
vendor_debian·2014·CVSS 7.8
CVE-2014-7844 [HIGH] CVE-2014-7844: bsd-mailx - BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary command...
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
Scope: local
bookworm: resolved (fixed in 8.1.2-0.20141216cvs-1)
bullseye: resolved (fixed in 8.1.2-0.20141216cvs-1)
forky: resolved (fixed in 8.1.2-0.20141216cvs-1)
sid: resolved (fixed in 8.1.2-0.20141216cvs-1)
trixie: resolved (fixed in 8.1.2-0.20141216cvs-1)
Apple
CVE-2014-7844: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 7.8
CVE-2014-7844 [HIGH] CVE-2014-7844: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-7844
Component: CVE-2014-7844
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
bugzilla·2014-12-17·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for nail: see blocks bug list for fu
Bugzilla
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw [fedora-all]
bugzilla·2014-12-16·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw [fedora-all]
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2004-2771 CVE-2014-7844 bsd-mailx: mailx: command execution flaw [epel-6]
bugzilla·2014-12-16·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 bsd-mailx: mailx: command execution flaw [epel-6]
CVE-2004-2771 CVE-2014-7844 bsd-mailx: mailx: command execution flaw [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for bsd-mailx: see blocks bug l
Bugzilla
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
bugzilla·2014-11-11·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
Florian Weimer from Red Hat has reported the below issue:
mailx executes shell commands embedded in syntactically valid mail addresses due a not quoted command to prevent word expansion.
fio.c
542 }
543 snprintf(cmdbuf, sizeof cmdbuf, "echo %s", name);
544 if ((shell = value("SHELL")) == NULL)
545 shell = SHELL;
The original report in Debian bugtracker:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748
Discussion:
Created attachment 958222
0001-outof-Introduce-expandaddr-flag.patch
---
Created attachment 958223
0002-unpack-Disable-option-processing-for-email-addresses.patch
---
Created attachment 958224
0003-fio.c-Unconditionally-require-wordexp-support.patch
---
Created attachment 958225
0004-globname-Invoke-wor
http://linux.oracle.com/errata/ELSA-2014-1999.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1999.htmlhttp://seclists.org/oss-sec/2014/q4/1066http://www.debian.org/security/2014/dsa-3104http://www.debian.org/security/2014/dsa-3105http://linux.oracle.com/errata/ELSA-2014-1999.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1999.htmlhttp://seclists.org/oss-sec/2014/q4/1066http://www.debian.org/security/2014/dsa-3104http://www.debian.org/security/2014/dsa-3105
2020-01-14
Published