CVE-2004-2771
טרם דורגה
תיאור (מקור, אנגלית)
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
מדדים
- EPSS — סבירות ניצול
- 7% (אחוזון 100) נכון ל-23/9/2026
- CWE
- CWE-20
מוצרים מושפעים
oracle: linux; redhat: enterprise linux; bsd_mailx_project: bsd mailx; heirloom: mailx
קישורים
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748 Exploit
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748 Exploit
- http://linux.oracle.com/errata/ELSA-2014-1999.html
- http://rhn.redhat.com/errata/RHSA-2014-1999.html
- http://seclists.org/oss-sec/2014/q4/1066
- http://secunia.com/advisories/60940
- http://secunia.com/advisories/61585
- http://secunia.com/advisories/61693
- http://www.debian.org/security/2014/dsa-3105
- http://linux.oracle.com/errata/ELSA-2014-1999.html