MGASA-2014-0538

Source
https://advisories.mageia.org/MGASA-2014-0538.html
Import Source
https://advisories.mageia.org/MGASA-2014-0538.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0538
Related
Published
2014-12-19T15:06:35Z
Modified
2014-12-19T14:58:45Z
Summary
Updated nail package fixes security vulnerabilities
Details

Updated nail package fixes security vulnerabilities:

A flaw was found in the way mailx handled the parsing of email addresses. A syntactically valid email address could allow a local attacker to cause mailx to execute arbitrary shell commands through shell meta-characters and the direct command execution functionality (CVE-2004-2771, CVE-2014-7844).

References
Credits

Affected packages

Mageia:4 / nail

Package

Name
nail
Purl
pkg:rpm/mageia/nail?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.4-9.1.mga4

Ecosystem specific

{
    "section": "core"
}