IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
https://www.exploit-db.com/exploits/40950/
http://www.securitytracker.com/id/1037480
http://www.securityfocus.com/bid/94979
http://aix.software.ibm.com/aix/efixes/security/bellmail_advisory.asc