Executive brief
A vulnerability exists in the mailx utility, a standard command-line tool used for sending and receiving email on Linux systems. A local attacker could exploit a timing flaw to gain unauthorized access to files belonging to other users on the same system. This could lead to the exposure of sensitive personal or system information.
Technical details
A race condition exists in the Linux mailx command. By exploiting a window of time during file operations, a local authenticated user can perform a symlink attack or similar race-based maneuver to intercept or read files they do not have permission to access. The attack requires local access and specific timing (High Access Complexity), resulting in a partial impact on confidentiality, integrity, and availability. This is a legacy vulnerability originally identified in 1995.
Affected products
- Linux mailx
Timeline
- 1995-12-01: disclosed: Initial publication date in NVD