Oval Definition:oval:org.mitre.oval:def:28385
Revision Date:2015-02-23Version:8
Title:RHSA-2014:1999 -- mailx security update (Moderate)
Description:The mailx packages contain a mail user agent that is used to manage mailusing scripts.A flaw was found in the way mailx handled the parsing of email addresses.A syntactically valid email address could allow a local attacker to causemailx to execute arbitrary shell commands through shell meta-characters andthe direct command execution functionality. (CVE-2004-2771, CVE-2014-7844)Note: Applications using mailx to send email to addresses obtained fromuntrusted sources will still remain vulnerable to other attacks if theyaccept email addresses which start with "-" (so that they can be confusedwith mailx options). To counteract this issue, this update also introducesthe "--" option, which will treat the remaining command line arguments asemail addresses.All mailx users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1999-CentOS 6
CESA-2014:1999-CentOS 7
CVE-2004-2771
CVE-2014-7844
RHSA-2014:1999
Platform(s):CentOS Linux 6
CentOS Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Product(s):mailx
Definition Synopsis
  • Red Hat Enterprise Linux 6 and CentOS Linux 6 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND mailx is earlier than 0:12.4-8.el6_6
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND mailx-debuginfo is earlier than 0:12.4-8.el6_6
  • Red Hat Enterprise Linux 7 and CentOS Linux 7 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • OR The operating system installed on the system is CentOS Linux 7.x
  • AND mailx is earlier than 0:12.5-12.el7_0
  • Red Hat Enterprise Linux 7 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • AND mailx-debuginfo is earlier than 0:12.5-12.el7_0
  • BACK