The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-113-1 | bsd-mailx security update |
Debian DLA |
DLA-114-1 | heirloom-mailx security update |
Debian DSA |
DSA-3104-1 | bsd-mailx security update |
Debian DSA |
DSA-3105-1 | heirloom-mailx security update |
EUVD |
EUVD-2004-2761 | The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-08T01:36:25.354Z
Reserved: 2012-01-04T00:00:00
Link: CVE-2004-2771
No data.
Status : Deferred
Published: 2014-12-24T18:59:00.103
Modified: 2025-04-12T10:46:40.837
Link: CVE-2004-2771
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD