Moderate CentOS mailx Security Update

Metadata

high
7.5
mailx-12.4-8.el6_6.i686.rpm, mailx-12.4-8.el6_6.src.rpm, mailx-12.4-8.el6_6.x86_64.rpm, mailx-12.5-12.el7_0.src.rpm, mailx-12.5-12.el7_0.x86_64.rpm
CVE-2004-2771, CVE-2014-7844
rhn.redhat.com, lists.centos.org, lists.centos.org
2014-12-16
2017-07-27 19:08
ALAS-2015-467
CVE-2004-2771 bsd-mailx
CVE-2014-7844 bsd-mailx
CVE-2014-7844 heirloom-mailx
CVE-2004-2771 heirloom-mailx
CVE-2014-7844
CVE-2004-2771
2017-04-01 19:08
2017-01-05 20:12

Description


Updated mailx packages that fix two security issues are now available for
Red Hat Enterprise Linux 6 and 7.

Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.

The mailx packages contain a mail user agent that is used to manage mail
using scripts.

A flaw was found in the way mailx handled the parsing of email addresses.
A syntactically valid email address could allow a local attacker to cause
mailx to execute arbitrary shell commands through shell meta-characters and
the direct command execution functionality. (CVE-2004-2771, CVE-2014-7844)

Note: Applications using mailx to send email to addresses obtained from
untrusted sources will still remain vulnerable to other attacks if they
accept email addresses which start with "-" (so that they can be confused
with mailx options). To counteract this issue, this update also introduces
the "--" option, which will treat the remaining command line arguments as
email addresses.

All mailx users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
6 mailx mailx-12.4-8.el6_6.i686.rpm
mailx mailx-12.4-8.el6_6.src.rpm
mailx mailx-12.4-8.el6_6.x86_64.rpm
7 mailx mailx-12.5-12.el7_0.src.rpm
mailx mailx-12.5-12.el7_0.x86_64.rpm