Bug#638002: Improper seteuid() calls in src/log.c and src/masqmail.c

2011-09-22 Thread Jonathan Wiltshire
Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.9) - use

Bug#638002: Improper seteuid() calls in src/log.c and src/masqmail.c

2011-08-16 Thread John Lightsey
Package: masqmail Version: 0.2.21-4 Severity: critical Tags: security Justification: root security hole Reporting publicly since this has already been disclosed on the masqmail list. In src/log.c there are two logging functions that use this logic: uid_t saved_uid; saved_uid =