CVE-2011-2910

MEDIUM

ax25-tools < 0.0.8-13 - Improper Privilege Management via setuid Call Failure

Title source: llm
STIX 2.1

Description

The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2011-2910
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2910

Scores

CVSS v3 6.7
EPSS 0.0037
EPSS Percentile 29.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (4)
debian/debian_linux 8.0
debian/debian_linux 9.0
debian/debian_linux 10.0
linux-ax25/ax25-tools < 0.0.8-13
Published Nov 15, 2019
Tracked Since Feb 18, 2026