cbcvebase.
CVE-2011-2910
published 2019-11-15

CVE-2011-2910: The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges…

PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.38%
30.2th percentile
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.

Affected

10 ranges
VendorProductVersion rangeFixed in
ax25-toolsax25-tools
ax25-toolsax25-tools>= 0 < 0.0.8-13.20.0.8-13.2
ax25-toolsax25-tools>= 0 < 0.0.8-13.20.0.8-13.2
ax25-toolsax25-tools>= 0 < 0.0.8-13.20.0.8-13.2
ax25-toolsax25-tools>= 0 < 0.0.8-13.20.0.8-13.2
debianax25-tools< ax25-tools 0.0.8-13.2 (bookworm)ax25-tools 0.0.8-13.2 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
linux-ax25ax25-tools< 0.0.8-130.0.8-13

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.