Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-3956


The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.


Published

2014-06-04T11:19:13.890

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 1.9 (LOW)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System freebsd freebsd ≤ 9.2 Yes
Application hp hpux ≤ b.11.31 Yes
Operating System fedoraproject fedora 20 Yes
Application sendmail sendmail ≤ 8.14.8 Yes
Application sendmail sendmail 8.6.7 Yes
Application sendmail sendmail 8.7.6 Yes
Application sendmail sendmail 8.7.7 Yes
Application sendmail sendmail 8.7.8 Yes
Application sendmail sendmail 8.7.9 Yes
Application sendmail sendmail 8.7.10 Yes
Application sendmail sendmail 8.8.8 Yes
Application sendmail sendmail 8.9.0 Yes
Application sendmail sendmail 8.9.1 Yes
Application sendmail sendmail 8.9.2 Yes
Application sendmail sendmail 8.9.3 Yes
Application sendmail sendmail 8.10 Yes
Application sendmail sendmail 8.10.0 Yes
Application sendmail sendmail 8.10.1 Yes
Application sendmail sendmail 8.10.2 Yes
Application sendmail sendmail 8.11.0 Yes
Application sendmail sendmail 8.11.1 Yes
Application sendmail sendmail 8.11.2 Yes
Application sendmail sendmail 8.11.3 Yes
Application sendmail sendmail 8.11.4 Yes
Application sendmail sendmail 8.11.5 Yes
Application sendmail sendmail 8.11.6 Yes
Application sendmail sendmail 8.11.7 Yes
Application sendmail sendmail 8.12.0 Yes
Application sendmail sendmail 8.12.1 Yes
Application sendmail sendmail 8.12.2 Yes
Application sendmail sendmail 8.12.3 Yes
Application sendmail sendmail 8.12.4 Yes
Application sendmail sendmail 8.12.5 Yes
Application sendmail sendmail 8.12.6 Yes
Application sendmail sendmail 8.12.7 Yes
Application sendmail sendmail 8.12.8 Yes
Application sendmail sendmail 8.12.9 Yes
Application sendmail sendmail 8.12.10 Yes
Application sendmail sendmail 8.12.11 Yes
Application sendmail sendmail 8.13.0 Yes
Application sendmail sendmail 8.13.1 Yes
Application sendmail sendmail 8.13.2 Yes
Application sendmail sendmail 8.13.3 Yes
Application sendmail sendmail 8.13.4 Yes
Application sendmail sendmail 8.13.5 Yes
Application sendmail sendmail 8.13.6 Yes
Application sendmail sendmail 8.13.7 Yes
Application sendmail sendmail 8.13.8 Yes
Application sendmail sendmail 8.14.0 Yes
Application sendmail sendmail 8.14.1 Yes
Application sendmail sendmail 8.14.2 Yes
Application sendmail sendmail 8.14.3 Yes
Application sendmail sendmail 8.14.4 Yes
Application sendmail sendmail 8.14.5 Yes
Application sendmail sendmail 8.14.6 Yes
Application sendmail sendmail 8.14.7 Yes

References