masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Masqmail | Marmaro | 0.2.21 (including) | 0.2.30 (including) |
Masqmail | Ubuntu | devel | * |
Masqmail | Ubuntu | hardy | * |
Masqmail | Ubuntu | lucid | * |
Masqmail | Ubuntu | maverick | * |
Masqmail | Ubuntu | natty | * |
Masqmail | Ubuntu | oneiric | * |
Masqmail | Ubuntu | precise | * |
Masqmail | Ubuntu | quantal | * |
Masqmail | Ubuntu | raring | * |
Masqmail | Ubuntu | saucy | * |
Masqmail | Ubuntu | upstream | * |