CVE-2014-7844

BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
6.6
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_eus
6.6
redhatenterprise_linux_server_eus
7.2
redhatenterprise_linux_server_eus
7.3
redhatenterprise_linux_server_eus
7.4
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_server_eus
7.6
redhatenterprise_linux_server_eus
7.7
redhatenterprise_linux_server_tus
6.6
redhatenterprise_linux_server_tus
7.3
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
debiandebian_linux
7.0
bsd_mailx_projectbsd_mailx
8.1.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bsd-mailx
bullseye
8.1.2-0.20180807cvs-2
fixed
sid
8.1.2-0.20220412cvs-1
fixed
trixie
8.1.2-0.20220412cvs-1
fixed
bookworm
8.1.2-0.20220412cvs-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bsd-mailx
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
Fixed 8.1.2-0.20131005cvs-1ubuntu0.14.10.1
released
trusty
Fixed 8.1.2-0.20131005cvs-1ubuntu0.14.04.1
released
precise
Fixed 8.1.2-0.20111106cvs-1ubuntu0.1
released
lucid
Fixed 8.1.2-0.20090911cvs-2ubuntu1.1
released
heirloom-mailx
zesty
dne
yakkety
dne
xenial
dne
wily
not-affected
vivid
ignored
utopic
Fixed 12.5-2+deb7u1build0.14.10.1
released
trusty
Fixed 12.5-2+deb7u1build0.14.04.1
released
precise
ignored
lucid
ignored