Lucene search

K
mageiaGentoo FoundationMGASA-2014-0270
HistoryJun 20, 2014 - 11:41 p.m.

Updated sendmail packages fix CVE-2014-3956

2014-06-2023:41:07
Gentoo Foundation
advisories.mageia.org
20

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

10.1%

Updated sendmail packages fix security vulnerability: Sendmail before 8.14.9 does not properly closing file descriptors before executing programs. This bug could enable local users to interfere with an open SMTP connection if they can execute their own program for mail delivery (e.g., via procmail or the prog mailer) (CVE-2014-3956).

OSVersionArchitecturePackageVersionFilename
Mageia3noarchsendmail< 8.14.6-2.1sendmail-8.14.6-2.1.mga3
Mageia4noarchsendmail< 8.14.7-3.1sendmail-8.14.7-3.1.mga4

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

10.1%