|
Message-ID: <538D1571.5020509@delphij.net> Date: Mon, 02 Jun 2014 17:23:13 -0700 From: Xin Li <delphij@...phij.net> To: oss-security@...ts.openwall.com CC: cve-assign@...re.org, gshapiro@...apiro.net Subject: sendmail close-on-exec issue -- CVE assigned? -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi, There is a security issue with sendmail which was fixed in 8.14.9 but there is no CVE to my knowledge: (Quote from ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES ) 8.14.9/8.14.9 2014/05/21 SECURITY: Properly set the close-on-exec flag for file descriptors (except stdin, stdout, and stderr) before executing mailers. Can someone confirm if there is no duplicate request for this and assign one if that's the case? (I have searched a few CVE databases and found nothing). Thanks in advance! Cheers, -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (FreeBSD) iQIcBAEBCgAGBQJTjRVxAAoJEJW2GBstM+nsT9kP/1MhlBSg9yc/KNpwp9pKF8Xj 5oM59xI4anSLn8JtKIcFojBaK+Mx+xQ5gkA8bKdGSS3uVSlpPH2MdoILleD9FAPn gRzW1bum4BeV2bGtJ5D92nql0uzpa7Mnxb6bhv/dY0H+KQzbZIC4SDZRCVbBGg+H QBCbCTTdNcBb5rKSkPpqRmR+FdEHhO8zYsVLpLOA6rmoi7Bn4T+g46U3SIgFh3yL bwsUrNTBtaHfslrl77/WwDz1qBTiirqfCKzuwxwSXvfxuaA0i5iglAs0fnaf6/Rm OVxhWOZklJmnLHCH3c/4IQkuiZNx8JTjqF9PxoGVsoHbjrDG6NCWjxKxdwrYSFTP nwNu3WoCpKjCf2AOnCC64iNshxkDDIfI/88F85uyxbrM9eGyLczPS5EKf2jBV3+x rMQWFVCodZ/843fLC00/bplQoBTbXivyqELOT8BSaYUNIohS/nOEmleToHislOOS S/9vTSvDFd5hHMqZF8eMfw1097tVcQjGFbW3/FHJ/wxr44zBcwrfz+trX5EV19Bg Ue6g8y6BpKu0ILVFR5jo9kGv8adq6zr5xrc0scUUiDrpyNoziKEpdGE7w6Dm1Lv7 voqrbVQqlhk6C9Lbtl2XDv3tamDUXe0bFvKVYMQwYqPIXvUz63wIBKso5WZpyYrC f5HNmNxh3ViQEUU5XeWn =ysYl -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.