{
  "schema_version": "1.7.0",
  "id": "MGASA-2014-0270",
  "published": "2014-06-20T19:41:07Z",
  "modified": "2014-06-20T19:40:54Z",
  "summary": "Updated sendmail packages fix CVE-2014-3956",
  "details": "Updated sendmail packages fix security vulnerability:\n\nSendmail before 8.14.9 does not properly closing file descriptors before\nexecuting programs. This bug could enable local users to interfere with\nan open SMTP connection if they can execute their own program for mail\ndelivery (e.g., via procmail or the prog mailer) (CVE-2014-3956).\n",
  "upstream": [
    "CVE-2014-3956"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2014-0270.html"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/pipermail/package-announce/2014-June/134349.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=13431"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:3",
        "name": "sendmail",
        "purl": "pkg:rpm/mageia/sendmail?arch=source&distro=mageia-3"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "8.14.6-2.1.mga3"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:4",
        "name": "sendmail",
        "purl": "pkg:rpm/mageia/sendmail?arch=source&distro=mageia-4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "8.14.7-3.1.mga4"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
