CVE-2014-3956

Source
https://cve.org/CVERecord?id=CVE-2014-3956
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2014-3956.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2014-3956
Downstream
Published
2014-06-04T11:19:13Z
Modified
2026-04-16T06:26:10.774765225Z
Summary
[none]
Details

The smcloseonexec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FDCLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.

References

Affected packages