Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <538D1571.5020509@delphij.net>
Date: Mon, 02 Jun 2014 17:23:13 -0700
From: Xin Li <delphij@...phij.net>
To: oss-security@...ts.openwall.com
CC: cve-assign@...re.org, gshapiro@...apiro.net
Subject: sendmail close-on-exec issue -- CVE assigned?

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

There is a security issue with sendmail which was fixed in 8.14.9 but
there is no CVE to my knowledge:

(Quote from ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES )

8.14.9/8.14.9	2014/05/21
	SECURITY: Properly set the close-on-exec flag for file
		descriptors (except stdin, stdout, and stderr) before
		executing mailers.

Can someone confirm if there is no duplicate request for this and
assign one if that's the case?  (I have searched a few CVE databases
and found nothing).

Thanks in advance!

Cheers,
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (FreeBSD)

iQIcBAEBCgAGBQJTjRVxAAoJEJW2GBstM+nsT9kP/1MhlBSg9yc/KNpwp9pKF8Xj
5oM59xI4anSLn8JtKIcFojBaK+Mx+xQ5gkA8bKdGSS3uVSlpPH2MdoILleD9FAPn
gRzW1bum4BeV2bGtJ5D92nql0uzpa7Mnxb6bhv/dY0H+KQzbZIC4SDZRCVbBGg+H
QBCbCTTdNcBb5rKSkPpqRmR+FdEHhO8zYsVLpLOA6rmoi7Bn4T+g46U3SIgFh3yL
bwsUrNTBtaHfslrl77/WwDz1qBTiirqfCKzuwxwSXvfxuaA0i5iglAs0fnaf6/Rm
OVxhWOZklJmnLHCH3c/4IQkuiZNx8JTjqF9PxoGVsoHbjrDG6NCWjxKxdwrYSFTP
nwNu3WoCpKjCf2AOnCC64iNshxkDDIfI/88F85uyxbrM9eGyLczPS5EKf2jBV3+x
rMQWFVCodZ/843fLC00/bplQoBTbXivyqELOT8BSaYUNIohS/nOEmleToHislOOS
S/9vTSvDFd5hHMqZF8eMfw1097tVcQjGFbW3/FHJ/wxr44zBcwrfz+trX5EV19Bg
Ue6g8y6BpKu0ILVFR5jo9kGv8adq6zr5xrc0scUUiDrpyNoziKEpdGE7w6Dm1Lv7
voqrbVQqlhk6C9Lbtl2XDv3tamDUXe0bFvKVYMQwYqPIXvUz63wIBKso5WZpyYrC
f5HNmNxh3ViQEUU5XeWn
=ysYl
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.