oval:org.mitre.oval:def:28385
Definition Id: oval:org.mitre.oval:def:28385 | |||
Oval ID: | oval:org.mitre.oval:def:28385 | ||
Title: | RHSA-2014:1999 -- mailx security update (Moderate) | ||
Description: | The mailx packages contain a mail user agent that is used to manage mail using scripts. A flaw was found in the way mailx handled the parsing of email addresses. A syntactically valid email address could allow a local attacker to cause mailx to execute arbitrary shell commands through shell meta-characters and the direct command execution functionality. (CVE-2004-2771, CVE-2014-7844) Note: Applications using mailx to send email to addresses obtained from untrusted sources will still remain vulnerable to other attacks if they accept email addresses which start with "-" (so that they can be confused with mailx options). To counteract this issue, this update also introduces the "--" option, which will treat the remaining command line arguments as email addresses. All mailx users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2014:1999 CESA-2014:1999-CentOS 6 CESA-2014:1999-CentOS 7 CVE-2004-2771 CVE-2014-7844 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 CentOS Linux 6 CentOS Linux 7 | Product(s): | mailx |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20273 | |||
Oval ID: | oval:org.mitre.oval:def:20273 | ||
Title: | The operating system installed on the system is Red Hat Enterprise Linux 6 | ||
Description: | The operating system installed on the system is Red Hat Enterprise Linux 6. | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:redhat:enterprise_linux:6 | Version: | 6 |
Platform(s): | Red Hat Enterprise Linux 6 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:28385 oval:org.mitre.oval:def:28385 |
Definition Id: oval:org.mitre.oval:def:16337 | |||
Oval ID: | oval:org.mitre.oval:def:16337 | ||
Title: | The operating system installed on the system is CentOS Linux 6.x | ||
Description: | The operating system installed on the system is CentOS Linux 6.x | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:centos:centos:6 | Version: | 5 |
Platform(s): | CentOS Linux 6 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:28385 |
Definition Id: oval:org.mitre.oval:def:24773 | |||
Oval ID: | oval:org.mitre.oval:def:24773 | ||
Title: | The operating system installed on the system is CentOS Linux 7.x | ||
Description: | The operating system installed on the system is CentOS Linux 7.x | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:centos:centos:7 | Version: | 3 |
Platform(s): | CentOS Linux 7 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:28385 |
Definition Id: oval:org.mitre.oval:def:24953 | |||
Oval ID: | oval:org.mitre.oval:def:24953 | ||
Title: | The operating system installed on the system is Red Hat Enterprise Linux 7 | ||
Description: | The operating system installed on the system is Red Hat Enterprise Linux 7. | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:redhat:enterprise_linux:7 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 7 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:28385 oval:org.mitre.oval:def:28385 |