BSD mailx CVE-2004-2771 Local Arbitrary Command Execution Vulnerability
BID:71704
Info
BSD mailx CVE-2004-2771 Local Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 71704 |
| Class: | Unknown |
| CVE: |
CVE-2004-2771 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 16 2014 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Seungbeom Kim |
| Vulnerable: |
Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux -current Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: | |
Discussion
BSD mailx CVE-2004-2771 Local Arbitrary Command Execution Vulnerability
BSD mailx is prone to a local arbitrary command-execution vulnerability.
Local attackers can exploit this issue to execute arbitrary commands on the underlying operating system.
BSD mailx is prone to a local arbitrary command-execution vulnerability.
Local attackers can exploit this issue to execute arbitrary commands on the underlying operating system.
References
BSD mailx CVE-2004-2771 Local Arbitrary Command Execution Vulnerability
References:
References:
- BSD Home Page (BSD)
- Bug 1162783 - (CVE-2004-2771, CVE-2014-7844) CVE-2004-2771 CVE-2014-7844 mailx: (Red Hat Bugzilla)
- mailx: unquoted recipient's name causes sending to fail (Debian)
- ASA-2015-015 (Avaya)
- Security Advisory, AlienVault v4.15.1 addresses twenty (20) vulnerabilities (AlienVault)