Lucene search

K
cve[email protected]CVE-2014-3956
HistoryJun 04, 2014 - 11:19 a.m.

CVE-2014-3956

2014-06-0411:19:13
CWE-200
web.nvd.nist.gov
209
cve-2014-3956
sendmail
security vulnerability
local users
file descriptors

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.2%

The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.

Affected configurations

NVD
Node
freebsdfreebsdRange9.2-
Node
hphpuxRangeb.11.31
Node
fedoraprojectfedoraMatch20
Node
sendmailsendmailRange8.14.8
OR
sendmailsendmailMatch8.6.7
OR
sendmailsendmailMatch8.7.6
OR
sendmailsendmailMatch8.7.7
OR
sendmailsendmailMatch8.7.8
OR
sendmailsendmailMatch8.7.9
OR
sendmailsendmailMatch8.7.10
OR
sendmailsendmailMatch8.8.8
OR
sendmailsendmailMatch8.9.0
OR
sendmailsendmailMatch8.9.1
OR
sendmailsendmailMatch8.9.2
OR
sendmailsendmailMatch8.9.3
OR
sendmailsendmailMatch8.10
OR
sendmailsendmailMatch8.10.0
OR
sendmailsendmailMatch8.10.1
OR
sendmailsendmailMatch8.10.2
OR
sendmailsendmailMatch8.11.0
OR
sendmailsendmailMatch8.11.1
OR
sendmailsendmailMatch8.11.2
OR
sendmailsendmailMatch8.11.3
OR
sendmailsendmailMatch8.11.4
OR
sendmailsendmailMatch8.11.5
OR
sendmailsendmailMatch8.11.6
OR
sendmailsendmailMatch8.11.7
OR
sendmailsendmailMatch8.12.0
OR
sendmailsendmailMatch8.12.1
OR
sendmailsendmailMatch8.12.2
OR
sendmailsendmailMatch8.12.3
OR
sendmailsendmailMatch8.12.4
OR
sendmailsendmailMatch8.12.5
OR
sendmailsendmailMatch8.12.6
OR
sendmailsendmailMatch8.12.7
OR
sendmailsendmailMatch8.12.8
OR
sendmailsendmailMatch8.12.9
OR
sendmailsendmailMatch8.12.10
OR
sendmailsendmailMatch8.12.11
OR
sendmailsendmailMatch8.13.0
OR
sendmailsendmailMatch8.13.1
OR
sendmailsendmailMatch8.13.2
OR
sendmailsendmailMatch8.13.3
OR
sendmailsendmailMatch8.13.4
OR
sendmailsendmailMatch8.13.5
OR
sendmailsendmailMatch8.13.6
OR
sendmailsendmailMatch8.13.7
OR
sendmailsendmailMatch8.13.8
OR
sendmailsendmailMatch8.14.0
OR
sendmailsendmailMatch8.14.1
OR
sendmailsendmailMatch8.14.2
OR
sendmailsendmailMatch8.14.3
OR
sendmailsendmailMatch8.14.4
OR
sendmailsendmailMatch8.14.5
OR
sendmailsendmailMatch8.14.6
OR
sendmailsendmailMatch8.14.7
CPENameOperatorVersion
freebsd:freebsdfreebsdle9.2

References

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.2%