The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade mailx | Dec 1, 2016 | Dec 24, 2014 |
| Debian | — | Upgrade bsd-mailxUpgrade heirloom-mailx | Jul 30, 2024 | Dec 24, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 10, 2015 |
| Gentoo Linux | — | Upgrade mail-client/mailx. | Apr 9, 2018 | Dec 24, 2014 |
| Oracle_linux | — | Upgrade mailx | Oct 16, 2024 | Dec 24, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 16, 2014 |
| Suse | — | Upgrade mailxUpgrade mailx-openssl1 | Dec 22, 2014 | Jun 28, 2013 |
| Ubuntu | — | Upgrade heirloom-mailx | Nov 19, 2024 | Dec 24, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub