CVE-2014-7844

Severity
7.8HIGH
EPSS
0.5%
top 32.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 17

Description

BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

Debianbsd-mailx< 8.1.2-0.20141216cvs-1+3
CVEListV5bsd/mailx8.1.2 and earlier

Also affects: Debian Linux 7.0, Enterprise Linux 6.6, 7.3, 7.4, 7.6, 7.7, 7.2, 7.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-v8v3-2m82-gr7p: BSD mailx 82022-05-17
CVEList
CVE-2014-7844: BSD mailx 82020-01-14
OSV
CVE-2014-7844: BSD mailx 82020-01-14

📋Vendor Advisories

5
Ubuntu
bsd-mailx vulnerability2015-01-07
Red Hat
mailx: command execution flaw2014-12-16
Red Hat
mailx: command execution flaw2014-12-16
Debian
CVE-2014-7844: bsd-mailx - BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary command...2014
Apple
CVE-2014-7844: OS X Yosemite v10.10.5 and Security Update 2015-006

💬Community

4
Bugzilla
CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]2014-12-17
Bugzilla
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw [fedora-all]2014-12-16
Bugzilla
CVE-2004-2771 CVE-2014-7844 bsd-mailx: mailx: command execution flaw [epel-6]2014-12-16
Bugzilla
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw2014-11-11