CVE-2014-3956
Last modified
CVE-2014-3956 is a vulnerability of currently unknown severity. The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | <= 9.2 |
| Hp | Hpux | <= b.11.31 |
| Fedoraproject | Fedora | 20 |
| Sendmail | Sendmail | <= 8.14.8 |
| Sendmail | Sendmail | 8.6.7 |
| Sendmail | Sendmail | 8.7.6 |
| Sendmail | Sendmail | 8.7.7 |
| Sendmail | Sendmail | 8.7.8 |
| Sendmail | Sendmail | 8.7.9 |
| Sendmail | Sendmail | 8.7.10 |
| Sendmail | Sendmail | 8.8.8 |
| Sendmail | Sendmail | 8.9.0 |
| Sendmail | Sendmail | 8.9.1 |
| Sendmail | Sendmail | 8.9.2 |
| Sendmail | Sendmail | 8.9.3 |
| Sendmail | Sendmail | 8.10 |
| Sendmail | Sendmail | 8.10.0 |
| Sendmail | Sendmail | 8.10.1 |
| Sendmail | Sendmail | 8.10.2 |
| Sendmail | Sendmail | 8.11.0 |
| Sendmail | Sendmail | 8.11.1 |
| Sendmail | Sendmail | 8.11.2 |
| Sendmail | Sendmail | 8.11.3 |
| Sendmail | Sendmail | 8.11.4 |
| Sendmail | Sendmail | 8.11.5 |
| Sendmail | Sendmail | 8.11.6 |
| Sendmail | Sendmail | 8.11.7 |
| Sendmail | Sendmail | 8.12.0 |
| Sendmail | Sendmail | 8.12.1 |
| Sendmail | Sendmail | 8.12.2 |
| Sendmail | Sendmail | 8.12.3 |
| Sendmail | Sendmail | 8.12.4 |
| Sendmail | Sendmail | 8.12.5 |
| Sendmail | Sendmail | 8.12.6 |
| Sendmail | Sendmail | 8.12.7 |
| Sendmail | Sendmail | 8.12.8 |
| Sendmail | Sendmail | 8.12.9 |
| Sendmail | Sendmail | 8.12.10 |
| Sendmail | Sendmail | 8.12.11 |
| Sendmail | Sendmail | 8.13.0 |
| Sendmail | Sendmail | 8.13.1 |
| Sendmail | Sendmail | 8.13.2 |
| Sendmail | Sendmail | 8.13.3 |
| Sendmail | Sendmail | 8.13.4 |
| Sendmail | Sendmail | 8.13.5 |
| Sendmail | Sendmail | 8.13.6 |
| Sendmail | Sendmail | 8.13.7 |
| Sendmail | Sendmail | 8.13.8 |
| Sendmail | Sendmail | 8.14.0 |
| Sendmail | Sendmail | 8.14.1 |
Showing 50 of 56 affected configurations. See NVD for the full list.
References
- ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTESVendor Advisory
- http://advisories.mageia.org/MGASA-2014-0270.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.htmlThird Party Advisory
- http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/67791Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030331Third Party Advisory, VDB Entry
- http://www.sendmail.com/sm/open_source/download/8.14.9/Patch, Vendor Advisory
- ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTESVendor Advisory
- http://advisories.mageia.org/MGASA-2014-0270.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.htmlThird Party Advisory
- http://packetstormsecurity.com/files/126975/Slackware-Security-Advisory-sendmail-Updates.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/67791Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030331Third Party Advisory, VDB Entry
- http://www.sendmail.com/sm/open_source/download/8.14.9/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3956?
How severe is CVE-2014-3956?
How do I fix CVE-2014-3956?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-3949Cross-site scripting (XSS) vulnerability in the layout wizar…
- CVE-2014-3951The HZ module in the iconv implementation in FreeBSD 10.0 be…
- CVE-2014-3952FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and …
- CVE-2014-3953FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and …
- CVE-2014-3954Stack-based buffer overflow in rtsold in FreeBSD 9.1 through…
- CVE-2014-3955routed in FreeBSD 8.4 through 10.1-RC2 allows remote attacke…
- CVE-2014-3959Cross-site scripting (XSS) vulnerability in list.jsp in the …
- CVE-2014-3960Multiple cross-site scripting (XSS) vulnerabilities in OpenN…
- CVE-2014-3961SQL injection vulnerability in the Export CSV page in the Pa…
- CVE-2014-3962Multiple SQL injection vulnerabilities in Videos Tube 1.0 al…
- CVE-2014-3963ownCloud Server before 6.0.1 does not properly check permiss…
- CVE-2014-3966Cross-site scripting (XSS) vulnerability in Special:Password…
Are you affected by CVE-2014-3956?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
