CVE-2004-2771
Summary
| CVE | CVE-2004-2771 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-12-24 18:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bsd Mailx Project | Bsd Mailx | All | All | All | All |
| Application | Heirloom | Mailx | All | All | All | All |
| Operating System | Oracle | Linux | 6 | All | All | All |
| Operating System | Oracle | Linux | 7 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3105-1 heirloom-mailx | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA61693 - Oracle Linux update for mailx - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| linux.oracle.com | ELSA-2014-1999 | af854a3a-2127-422b-91ae-364da2661108 | linux.oracle.com | |
| Security Advisory SA60940 - Debian update for heirloom-mailx - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| #278748 - mailx: unquoted recipient's name causes sending to fail - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Exploit |
| Security Advisory SA61585 - Red Hat update for mailx - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-sec: mailx issues (CVE-2004-2771, CVE-2014-7844) | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2004-2771 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 1162783 – (CVE-2004-2771, CVE-2014-7844) CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.