CVE-2014-3956

low
Published 2014-06-04 · Modified 2026-05-06
CVSS v3
CVSS v2
1.9
VIR risk
1.9

Description

The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-3956

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.sendmail.com/sm/open_source/download/8.14.9/

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES

OS impact

OSVersionStatusFixed in
fedora fedora20affected
freebsd freebsdaffected
debian debianbookwormfixed8.14.4-6
debian debianbullseyefixed8.14.4-6
debian debianforkyfixed8.14.4-6
debian debiansidfixed8.14.4-6
debian debiantrixiefixed8.14.4-6

Application impact

VendorProductVersionsFixed
hp hphpux{"endIncluding":"b.11.31"}
sendmailsendmail{"endIncluding":"8.14.8"}
sendmailsendmail8.6.7
sendmailsendmail8.7.6
sendmailsendmail8.7.7
sendmailsendmail8.7.8
sendmailsendmail8.7.9
sendmailsendmail8.7.10
sendmailsendmail8.8.8
sendmailsendmail8.9.0
sendmailsendmail8.9.1
sendmailsendmail8.9.2
sendmailsendmail8.9.3
sendmailsendmail8.10
sendmailsendmail8.10.0
sendmailsendmail8.10.1
sendmailsendmail8.10.2
sendmailsendmail8.11.0
sendmailsendmail8.11.1
sendmailsendmail8.11.2
sendmailsendmail8.11.3
sendmailsendmail8.11.4
sendmailsendmail8.11.5
sendmailsendmail8.11.6
sendmailsendmail8.11.7
sendmailsendmail8.12.0
sendmailsendmail8.12.1
sendmailsendmail8.12.2
sendmailsendmail8.12.3
sendmailsendmail8.12.4
sendmailsendmail8.12.5
sendmailsendmail8.12.6
sendmailsendmail8.12.7
sendmailsendmail8.12.8
sendmailsendmail8.12.9
sendmailsendmail8.12.10
sendmailsendmail8.12.11
sendmailsendmail8.13.0
sendmailsendmail8.13.1
sendmailsendmail8.13.2
sendmailsendmail8.13.3
sendmailsendmail8.13.4
sendmailsendmail8.13.5
sendmailsendmail8.13.6
sendmailsendmail8.13.7
sendmailsendmail8.13.8
sendmailsendmail8.14.0
sendmailsendmail8.14.1
sendmailsendmail8.14.2
sendmailsendmail8.14.3
sendmailsendmail8.14.4
sendmailsendmail8.14.5
sendmailsendmail8.14.6
sendmailsendmail8.14.7

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.