The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < a63907c8c712414643b597debcd09d16b6827b23 |