Debian Security Advisory DSA 848-1 - Jens Steube discovered two vulnerabilities in masqmail, a mailer for hosts without permanent internet connection. When sending failed mail messages, the address is not sanitized, which allows a local attacker to execute arbitrary commands as the mail user. When opening the log file, masqmail does not relinquish privileges, which allows a local attacker to overwrite arbitrary files via a symlink attack.
f7f59ad84fbb01fe499aa54d77b5c6413626d30e33b3ee7d24987261d3132c5b