buildroot ▾
›
master ▾
›
vulnerability
›
CVE-2004-2771
Component Overview
Vulnerability Overview
Name
CVE-2004-2771
Source
NVD (
link
)
Debian (
link
)
Description
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
CWEs
CWE-20
Published Date
Dec 24, 2014
Updated Date
Jun 16, 2026
Workaround
-
Advisories
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748
Exploit
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748
Exploit
Analysis
#
Affected Component
Analysis
heirloom-mailx
Patched
Vulnerability Rating
#
7.5
CVSSv2
Others affected component
#
Name
Project
Project Version
Version
Status
heirloom-mailx
buildroot
2025.02.x
12.5
Patched
Resolved with patches
#
heirloom-mailx (buildroot:2025.02.x)
#
Title
Author
Resolve
1
globname: Invoke wordexp with WRDE_NOCMD (CVE-2004-2771)
Florian Weimer <fweimer@redhat.com>
CVE-2004-2771
heirloom-mailx (buildroot:master)
#
Title
Author
Resolve
1
globname: Invoke wordexp with WRDE_NOCMD (CVE-2004-2771)
Florian Weimer <fweimer@redhat.com>
CVE-2004-2771