CVE-2014-3956

sendmail <8.14.9 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.

References (17)

Core 17
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58628
Vendor Advisory vendor-advisory x_refsource_freebsd
http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.asc
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:128
Vendor Advisory x_refsource_confirm
ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201412-32.xml
Patch, Vendor Advisory x_refsource_confirm
http://www.sendmail.com/sm/open_source/download/8.14.9/
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-06/msg00032.html
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2014:147
Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.html
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-06/msg00033.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57455
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67791
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2014-0270.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030331

Scores

EPSS 0.0008
EPSS Percentile 23.5%

Details

CWE
CWE-200
Status published
Products (50)
fedoraproject/fedora 20
freebsd/freebsd < 9.2
hp/hpux < b.11.31
sendmail/sendmail 8.6.7
sendmail/sendmail 8.7.6
sendmail/sendmail 8.7.7
sendmail/sendmail 8.7.8
sendmail/sendmail 8.7.9
sendmail/sendmail 8.7.10
sendmail/sendmail 8.8.8
... and 40 more
Published Jun 04, 2014
Tracked Since Feb 18, 2026