CVE-2014-3956
published 2014-06-04CVE-2014-3956: The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags…
PriorityP47low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.63%
46.1th percentile
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sendmail | < sendmail 8.14.4-6 (bookworm) | sendmail 8.14.4-6 (bookworm) |
| fedoraproject | fedora | — | — |
| freebsd | freebsd | <= 9.2 | — |
| hp | hpux | <= b.11.31 | — |
| sendmail | sendmail | <= 8.14.8 | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
| sendmail | sendmail | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-frwj-4rf4-3wjf: The sm_close_on_exec function in conf
ghsa_unreviewed·2022-05-17
CVE-2014-3956 [LOW] CWE-200 GHSA-frwj-4rf4-3wjf: The sm_close_on_exec function in conf
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
OSV
CVE-2014-3956: The sm_close_on_exec function in conf
osv·2014-06-04·CVSS 1.9
CVE-2014-3956 [LOW] CVE-2014-3956: The sm_close_on_exec function in conf
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
Red Hat
sendmail: Properly set the close-on-exec flag for file descriptors
vendor_redhat·2014-05-21·CVSS 1.9
CVE-2014-3956 [LOW] sendmail: Properly set the close-on-exec flag for file descriptors
sendmail: Properly set the close-on-exec flag for file descriptors
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
Statement: This issue affects the versions of sendmail as shipped with Red Hat Enterprise Linux 4, 5, 6, and 7. Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: sendmail (Red Hat Enterprise Linux 4) - Affected
Package:
Debian
CVE-2014-3956: sendmail - The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments ...
vendor_debian·2014·CVSS 1.9
CVE-2014-3956 [LOW] CVE-2014-3956: sendmail - The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments ...
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
Scope: local
bookworm: resolved (fixed in 8.14.4-6)
bullseye: resolved (fixed in 8.14.4-6)
forky: resolved (fixed in 8.14.4-6)
sid: resolved (fixed in 8.14.4-6)
trixie: resolved (fixed in 8.14.4-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3956 npm: bearer token leak to non-registry hosts
bugzilla·2016-04-19·CVSS 7.5
CVE-2016-3956 [HIGH] CVE-2016-3956 npm: bearer token leak to non-registry hosts
CVE-2016-3956 npm: bearer token leak to non-registry hosts
The primary npm registry has, since late 2014, used HTTP bearer tokens to authenticate requests from the npm command-line interface. Due to a design flaw in the CLI, these bearer tokens were sent with every request made by the CLI for logged-in users, regardless of the destination of the request. They should instead only be included for requests made against the registry or registries used for the current install.
This flaw allows an attacker to set up an HTTP server that could collect authentication information they could use to impersonate the users whose tokens they collected. This impersonation would allow them to do anything the compromised users could do, including publishing new versions of packages.
External references:
Bugzilla
CVE-2014-3956 sendmail: Properly set the close-on-exec flag for file descriptors [fedora-all]
bugzilla·2014-06-04·CVSS 1.9
CVE-2014-3956 [LOW] CVE-2014-3956 sendmail: Properly set the close-on-exec flag for file descriptors [fedora-all]
CVE-2014-3956 sendmail: Properly set the close-on-exec flag for file descriptors [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue a
Bugzilla
CVE-2014-3956 sendmail: Properly set the close-on-exec flag for file descriptors
bugzilla·2014-05-28·CVSS 1.9
CVE-2014-3956 [LOW] CVE-2014-3956 sendmail: Properly set the close-on-exec flag for file descriptors
CVE-2014-3956 sendmail: Properly set the close-on-exec flag for file descriptors
Upstream released version 8.14.9 of sendmail [1] which fixes one security related bug by properly closing file descriptors (except stdin, stdout, and stderr) before executing programs. This bug could enable local users to interfere with an open SMTP connection if they can execute their own program for mail delivery (e.g., via procmail or the prog mailer).
[1]: http://www.sendmail.com/sm/open_source/download/8.14.9/?show_rs=1
Discussion:
Created attachment 900848
patch generated from diff of 8.14.8 to 8.14.9
I can't find a CVS repository for sendmail, so this was generated by manually diffing and removing everything that was obviously not related. This seems to be the required patch.
---
Thanks for the d
ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTEShttp://advisories.mageia.org/MGASA-2014-0270.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00033.htmlhttp://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.htmlhttp://secunia.com/advisories/57455http://secunia.com/advisories/58628http://security.gentoo.org/glsa/glsa-201412-32.xmlhttp://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.aschttp://www.mandriva.com/security/advisories?name=MDVSA-2014:147http://www.mandriva.com/security/advisories?name=MDVSA-2015:128http://www.securityfocus.com/bid/67791http://www.securitytracker.com/id/1030331http://www.sendmail.com/sm/open_source/download/8.14.9/http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.728644https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTEShttp://advisories.mageia.org/MGASA-2014-0270.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00033.htmlhttp://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.htmlhttp://secunia.com/advisories/57455http://secunia.com/advisories/58628http://security.gentoo.org/glsa/glsa-201412-32.xmlhttp://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A11.sendmail.aschttp://www.mandriva.com/security/advisories?name=MDVSA-2014:147http://www.mandriva.com/security/advisories?name=MDVSA-2015:128http://www.securityfocus.com/bid/67791http://www.securitytracker.com/id/1030331http://www.sendmail.com/sm/open_source/download/8.14.9/http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.728644https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05216368
2014-06-04
Published