Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 02 Jun 2014 17:23:13 -0700
From: Xin Li <delphij@...phij.net>
To: oss-security@...ts.openwall.com
CC: cve-assign@...re.org, gshapiro@...apiro.net
Subject: sendmail close-on-exec issue -- CVE assigned?

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

There is a security issue with sendmail which was fixed in 8.14.9 but
there is no CVE to my knowledge:

(Quote from ftp://ftp.sendmail.org/pub/sendmail/RELEASE_NOTES )

8.14.9/8.14.9	2014/05/21
	SECURITY: Properly set the close-on-exec flag for file
		descriptors (except stdin, stdout, and stderr) before
		executing mailers.

Can someone confirm if there is no duplicate request for this and
assign one if that's the case?  (I have searched a few CVE databases
and found nothing).

Thanks in advance!

Cheers,
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (FreeBSD)

iQIcBAEBCgAGBQJTjRVxAAoJEJW2GBstM+nsT9kP/1MhlBSg9yc/KNpwp9pKF8Xj
5oM59xI4anSLn8JtKIcFojBaK+Mx+xQ5gkA8bKdGSS3uVSlpPH2MdoILleD9FAPn
gRzW1bum4BeV2bGtJ5D92nql0uzpa7Mnxb6bhv/dY0H+KQzbZIC4SDZRCVbBGg+H
QBCbCTTdNcBb5rKSkPpqRmR+FdEHhO8zYsVLpLOA6rmoi7Bn4T+g46U3SIgFh3yL
bwsUrNTBtaHfslrl77/WwDz1qBTiirqfCKzuwxwSXvfxuaA0i5iglAs0fnaf6/Rm
OVxhWOZklJmnLHCH3c/4IQkuiZNx8JTjqF9PxoGVsoHbjrDG6NCWjxKxdwrYSFTP
nwNu3WoCpKjCf2AOnCC64iNshxkDDIfI/88F85uyxbrM9eGyLczPS5EKf2jBV3+x
rMQWFVCodZ/843fLC00/bplQoBTbXivyqELOT8BSaYUNIohS/nOEmleToHislOOS
S/9vTSvDFd5hHMqZF8eMfw1097tVcQjGFbW3/FHJ/wxr44zBcwrfz+trX5EV19Bg
Ue6g8y6BpKu0ILVFR5jo9kGv8adq6zr5xrc0scUUiDrpyNoziKEpdGE7w6Dm1Lv7
voqrbVQqlhk6C9Lbtl2XDv3tamDUXe0bFvKVYMQwYqPIXvUz63wIBKso5WZpyYrC
f5HNmNxh3ViQEUU5XeWn
=ysYl
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ