← Back

CVE-2014-3956

nvd nist
Published: Jun 4, 2014Modified: May 6, 2026

JSON object

Loading...
1.9
Vector
AV:L/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 3.4 / Impact: 2.9
Source: NVD

Description

The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.

Affected (56)

Products: Freebsd: Freebsd · Hp: Hpux · Fedoraproject: Fedora · +1 more
Show all products
1 product
Freebsd
1 product
Hpux
1 product
Fedora
1 product
Sendmail
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 9.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to b.11.31
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 20
Configuration D
53 vulnerable
Vulnerable SoftwareAffected Versions
Sendmail
Up to 8.14.8
Version 8.10.0
Version 8.10.1
Version 8.10.2
Version 8.10
Version 8.11.0
Version 8.11.1
Version 8.11.2
Version 8.11.3
Version 8.11.4
Version 8.11.5
Version 8.11.6
Version 8.11.7
Version 8.12.0
Version 8.12.10
Version 8.12.11
Version 8.12.1
Version 8.12.2
Version 8.12.3
Version 8.12.4
Version 8.12.5
Version 8.12.6
Version 8.12.7
Version 8.12.8
Version 8.12.9
Version 8.13.0
Version 8.13.1
Version 8.13.2
Version 8.13.3
Version 8.13.4
Version 8.13.5
Version 8.13.6
Version 8.13.7
Version 8.13.8
Version 8.14.0
Version 8.14.1
Version 8.14.2
Version 8.14.3
Version 8.14.4
Version 8.14.5
Version 8.14.6
Version 8.14.7
Version 8.6.7
Version 8.7.10
Version 8.7.6
Version 8.7.7
Version 8.7.8
Version 8.7.9
Version 8.8.8
Version 8.9.0
Version 8.9.1
Version 8.9.2
Version 8.9.3

References (34)

ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES (unsafe URL)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
PatchVendor Advisory
ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.