---
id: CVE-2004-2771
title: >-
  The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx
  8.1.2 and earlier allows remote attackers to execute arbitrary commands via
  shell metacharacters in an email address.
summary: >-
  The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx
  8.1.2 and earlier allows remote attackers to execute arbitrary commands via
  shell metacharacters in an email address.
severity: high
cvss: 7.5
cvssVector: 'AV:N/AC:L/Au:N/C:P/I:P/A:P'
cwe:
  - CWE-20
vendor: bsd_mailx_project
product: bsd_mailx
affected:
  - linux = 6
  - linux = 7
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - bsd_mailx <= 8.1.2
  - mailx <= 12.5
published: '2014-12-24'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T13:10:00.153'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2004-2771'
references:
  - url: 'http://linux.oracle.com/errata/ELSA-2014-1999.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-1999.html'
    label: secalert@redhat.com
  - url: 'http://seclists.org/oss-sec/2014/q4/1066'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/60940'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/61585'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/61693'
    label: secalert@redhat.com
  - url: 'http://www.debian.org/security/2014/dsa-3105'
    label: secalert@redhat.com
  - url: 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748'
    label: secalert@redhat.com
  - url: 'http://linux.oracle.com/errata/ELSA-2014-1999.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-1999.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/oss-sec/2014/q4/1066'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/60940'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/61585'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/61693'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.debian.org/security/2014/dsa-3105'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.06858
epssPercentile: 0.93755
ingestedAt: '2026-09-23T13:24:43.387Z'
---

## Overview

The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

## Affected

- `linux = 6`
- `linux = 7`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `bsd_mailx <= 8.1.2`
- `mailx <= 12.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
