Logo
componentheirloom-mailx
Name
heirloom-mailx
Version
12.5
Type
library
Description
-
Licenses
BSD-4-ClauseBellcore (base64)OpenVision (imap_gssapi)RSA Data Security (md5)Network Working Group (hmac)MPL-1.1 (nss)
PURL
-
CPE
cpe:2.3:a:heirloom:mailx:12.5:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
12.5

Patches#


#
Title
Author
Resolve
1
Don't reuse weak symbol optopt to fix FTBFS on mips*
Luk Claes <luk@debian.org>
2
Patched out SSL2 support since it is no longer supported by OpenSSL.
Hilko Bengen <bengen@debian.org>
3
Fixed Lintian warning (warning: macro `N' not defined)
Hilko Bengen <bengen@debian.org>
4
outof: Introduce expandaddr flag
Florian Weimer <fweimer@redhat.com>
CVE-2014-7844
5
unpack: Disable option processing for email addresses
Florian Weimer <fweimer@redhat.com>
6
fio.c: Unconditionally require wordexp support
Florian Weimer <fweimer@redhat.com>
7
globname: Invoke wordexp with WRDE_NOCMD (CVE-2004-2771)
Florian Weimer <fweimer@redhat.com>
CVE-2004-2771
8
Patch #8
Thomas Perale <thomas.perale@mind.be>
9
fix libressl support
Adam Duskett <aduskett@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Patched
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
Patched
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.