// For flags

CVE-2014-3956

 

Severity Score

1.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.

La función sm_close_on_exec en conf.c en sendmail anterior a 8.14.9 tiene argumentos en el orden erróneo, y como consecuencia evade configurar etiquetas FD_CLOEXEC esperadas, lo que permite a usuarios locales acceder a descriptores de archivos de número alto no intencionados a través de un programa de entrega de correo personalizado.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-06-03 CVE Reserved
  • 2014-06-04 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Freebsd
Search vendor "Freebsd"
Freebsd
Search vendor "Freebsd" for product "Freebsd"
<= 9.2
Search vendor "Freebsd" for product "Freebsd" and version " <= 9.2"
-
Affected
Hp
Search vendor "Hp"
Hpux
Search vendor "Hp" for product "Hpux"
<= b.11.31
Search vendor "Hp" for product "Hpux" and version " <= b.11.31"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
20
Search vendor "Fedoraproject" for product "Fedora" and version "20"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
<= 8.14.8
Search vendor "Sendmail" for product "Sendmail" and version " <= 8.14.8"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.6.7
Search vendor "Sendmail" for product "Sendmail" and version "8.6.7"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.7.6
Search vendor "Sendmail" for product "Sendmail" and version "8.7.6"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.7.7
Search vendor "Sendmail" for product "Sendmail" and version "8.7.7"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.7.8
Search vendor "Sendmail" for product "Sendmail" and version "8.7.8"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.7.9
Search vendor "Sendmail" for product "Sendmail" and version "8.7.9"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.7.10
Search vendor "Sendmail" for product "Sendmail" and version "8.7.10"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.8.8
Search vendor "Sendmail" for product "Sendmail" and version "8.8.8"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.9.0
Search vendor "Sendmail" for product "Sendmail" and version "8.9.0"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.9.1
Search vendor "Sendmail" for product "Sendmail" and version "8.9.1"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.9.2
Search vendor "Sendmail" for product "Sendmail" and version "8.9.2"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.9.3
Search vendor "Sendmail" for product "Sendmail" and version "8.9.3"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.10
Search vendor "Sendmail" for product "Sendmail" and version "8.10"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.10.0
Search vendor "Sendmail" for product "Sendmail" and version "8.10.0"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.10.1
Search vendor "Sendmail" for product "Sendmail" and version "8.10.1"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.10.2
Search vendor "Sendmail" for product "Sendmail" and version "8.10.2"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.11.0
Search vendor "Sendmail" for product "Sendmail" and version "8.11.0"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.11.1
Search vendor "Sendmail" for product "Sendmail" and version "8.11.1"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.11.2
Search vendor "Sendmail" for product "Sendmail" and version "8.11.2"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.11.3
Search vendor "Sendmail" for product "Sendmail" and version "8.11.3"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.11.4
Search vendor "Sendmail" for product "Sendmail" and version "8.11.4"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.11.5
Search vendor "Sendmail" for product "Sendmail" and version "8.11.5"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.11.6
Search vendor "Sendmail" for product "Sendmail" and version "8.11.6"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.11.7
Search vendor "Sendmail" for product "Sendmail" and version "8.11.7"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.0
Search vendor "Sendmail" for product "Sendmail" and version "8.12.0"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.1
Search vendor "Sendmail" for product "Sendmail" and version "8.12.1"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.2
Search vendor "Sendmail" for product "Sendmail" and version "8.12.2"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.3
Search vendor "Sendmail" for product "Sendmail" and version "8.12.3"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.4
Search vendor "Sendmail" for product "Sendmail" and version "8.12.4"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.5
Search vendor "Sendmail" for product "Sendmail" and version "8.12.5"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.6
Search vendor "Sendmail" for product "Sendmail" and version "8.12.6"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.7
Search vendor "Sendmail" for product "Sendmail" and version "8.12.7"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.8
Search vendor "Sendmail" for product "Sendmail" and version "8.12.8"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.9
Search vendor "Sendmail" for product "Sendmail" and version "8.12.9"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.10
Search vendor "Sendmail" for product "Sendmail" and version "8.12.10"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.12.11
Search vendor "Sendmail" for product "Sendmail" and version "8.12.11"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.0
Search vendor "Sendmail" for product "Sendmail" and version "8.13.0"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.1
Search vendor "Sendmail" for product "Sendmail" and version "8.13.1"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.2
Search vendor "Sendmail" for product "Sendmail" and version "8.13.2"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.3
Search vendor "Sendmail" for product "Sendmail" and version "8.13.3"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.4
Search vendor "Sendmail" for product "Sendmail" and version "8.13.4"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.5
Search vendor "Sendmail" for product "Sendmail" and version "8.13.5"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.6
Search vendor "Sendmail" for product "Sendmail" and version "8.13.6"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.7
Search vendor "Sendmail" for product "Sendmail" and version "8.13.7"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.13.8
Search vendor "Sendmail" for product "Sendmail" and version "8.13.8"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.14.0
Search vendor "Sendmail" for product "Sendmail" and version "8.14.0"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.14.1
Search vendor "Sendmail" for product "Sendmail" and version "8.14.1"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.14.2
Search vendor "Sendmail" for product "Sendmail" and version "8.14.2"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.14.3
Search vendor "Sendmail" for product "Sendmail" and version "8.14.3"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.14.4
Search vendor "Sendmail" for product "Sendmail" and version "8.14.4"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.14.5
Search vendor "Sendmail" for product "Sendmail" and version "8.14.5"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.14.6
Search vendor "Sendmail" for product "Sendmail" and version "8.14.6"
-
Affected
Sendmail
Search vendor "Sendmail"
Sendmail
Search vendor "Sendmail" for product "Sendmail"
8.14.7
Search vendor "Sendmail" for product "Sendmail" and version "8.14.7"
-
Affected