masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2011-3350 | third party advisory |
https://access.redhat.com/security/cve/cve-2011-3350 | broken link |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=638002 | issue tracking third party advisory |