Unrated severityNVD Advisory· Published Jun 4, 2014· Updated May 6, 2026
CVE-2014-3956
CVE-2014-3956
Description
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
Affected products
56cpe:2.3:a:sendmail:sendmail:*:*:*:*:*:*:*:*+ 52 more
- cpe:2.3:a:sendmail:sendmail:*:*:*:*:*:*:*:*range: <=8.14.8
- cpe:2.3:a:sendmail:sendmail:8.10:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.10.2:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.11.2:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.11.3:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.11.4:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.11.5:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.11.6:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.11.7:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.10:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.11:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.2:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.3:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.4:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.5:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.6:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.7:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.8:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.12.9:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.0:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.1:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.2:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.3:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.4:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.5:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.6:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.7:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.13.8:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.14.1:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.14.2:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.14.3:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.14.4:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.14.5:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.14.6:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.14.7:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.7.10:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.7.6:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.7.7:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.7.8:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.7.9:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.8.8:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:sendmail:sendmail:8.9.3:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- www.sendmail.com/sm/open_source/download/8.14.9/nvdPatchVendor Advisory
- ftp.sendmail.org/pub/sendmail/RELEASE_NOTESnvdVendor Advisory
- advisories.mageia.org/MGASA-2014-0270.htmlnvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.htmlnvdThird Party Advisory
- packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.htmlnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/67791nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1030331nvdThird Party AdvisoryVDB Entry
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party Advisory
- lists.opensuse.org/opensuse-updates/2014-06/msg00032.htmlnvd
- lists.opensuse.org/opensuse-updates/2014-06/msg00033.htmlnvd
- secunia.com/advisories/57455nvd
- secunia.com/advisories/58628nvd
- security.gentoo.org/glsa/glsa-201412-32.xmlnvd
- www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.ascnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.slackware.com/security/viewer.phpnvd
News mentions
0No linked articles in our index yet.