-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 _______________________________________________________________________ Mandriva Linux Security Advisory MDVSA-2014:147 http://www.mandriva.com/en/support/security/ _______________________________________________________________________ Package : sendmail Date : July 31, 2014 Affected: Business Server 1.0 _______________________________________________________________________ Problem Description: Updated sendmail packages fix security vulnerability: Sendmail before 8.14.9 does not properly closing file descriptors before executing programs. This bug could enable local users to interfere with an open SMTP connection if they can execute their own program for mail delivery (e.g., via procmail or the prog mailer) (CVE-2014-3956). _______________________________________________________________________ References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3956 http://advisories.mageia.org/MGASA-2014-0270.html _______________________________________________________________________ Updated Packages: Mandriva Business Server 1/X86_64: 9f87330fbfb62d7ae3b22b0cada29c52 mbs1/x86_64/sendmail-8.14.6-2.1.mbs1.x86_64.rpm 7c54405a5aad8b5d269f826dcedf3815 mbs1/x86_64/sendmail-cf-8.14.6-2.1.mbs1.x86_64.rpm 82b6adad99a9e24e8d1ce9be4169c02c mbs1/x86_64/sendmail-devel-8.14.6-2.1.mbs1.x86_64.rpm 7351c18b5763064dd79d4e750e1b0a83 mbs1/x86_64/sendmail-doc-8.14.6-2.1.mbs1.x86_64.rpm ae7f0df3cc9fac2f0586184bf5eaf382 mbs1/SRPMS/sendmail-8.14.6-2.1.mbs1.src.rpm _______________________________________________________________________ To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/en/support/security/advisories/ If you want to report vulnerabilities, please contact security_(at)_mandriva.com _______________________________________________________________________ Type Bits/KeyID Date User ID pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iD8DBQFT2gz3mqjQ0CJFipgRAuZDAJ9arMIYKjF9sD2MNz051quy/gx7YACgxVAt BpmuxuyJoiM1vWndD1+k5zY= =T6gv -----END PGP SIGNATURE-----