CVE-2004-2771 describes a command injection vulnerability in the expand function of fio.c within Heirloom mailx (12.5 and earlier) and BSD mailx (8.1.2 and earlier), allowing remote attackers to execute arbitrary commands through shell metacharacters in email addresses. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network without authentication, potentially leading to partial compromise of confidentiality, integrity, and availability. Despite its age and high media coverage for its time, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, indicating low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6CPE matchmatch criteria | cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
<= 8.1.2CPE matchmatch criteria | cpe:2.3:a:bsd_mailx_project:bsd_mailx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2004-2771
Jun 11, 2024CVE-2004-2771
Dec 14, 2021mailx: command execution flaw
Dec 16, 2014The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
Dec 2, 2014