MasqMail Multiple Local Privilege Escalation Vulnerabilities
BID:49181
Info
MasqMail Multiple Local Privilege Escalation Vulnerabilities
| Bugtraq ID: | 49181 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 17 2011 12:00AM |
| Updated: | Sep 07 2011 04:50PM |
| Credit: | John Lightsey |
| Vulnerable: |
MasqMail MasqMail 0.2.29 |
| Not Vulnerable: |
MasqMail MasqMail 0.2.30 |
Discussion
MasqMail Multiple Local Privilege Escalation Vulnerabilities
MasqMail is prone to multiple local privilege-escalation vulnerabilities.
Local attackers can exploit these issues to execute arbitrary code with elevated privileges. Successful exploits may compromise affected computers.
MasqMail 0.2.29 is vulnerable; other versions may also be affected.
MasqMail is prone to multiple local privilege-escalation vulnerabilities.
Local attackers can exploit these issues to execute arbitrary code with elevated privileges. Successful exploits may compromise affected computers.
MasqMail 0.2.29 is vulnerable; other versions may also be affected.
Exploit / POC
MasqMail Multiple Local Privilege Escalation Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
MasqMail Multiple Local Privilege Escalation Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
MasqMail Multiple Local Privilege Escalation Vulnerabilities
References:
References:
- Improper seteuid() calls in src/log.c and src/masqmail.c (John Lightsey)
- Re: Possible security bug in masqmail (markus schnalke)
- Vendor Homepage (MasqMail)