CVE-2011-2910
published 2019-11-15CVE-2011-2910: The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.38%
30.2th percentile
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ax25-tools | ax25-tools | — | — |
| ax25-tools | ax25-tools | >= 0 < 0.0.8-13.2 | 0.0.8-13.2 |
| ax25-tools | ax25-tools | >= 0 < 0.0.8-13.2 | 0.0.8-13.2 |
| ax25-tools | ax25-tools | >= 0 < 0.0.8-13.2 | 0.0.8-13.2 |
| ax25-tools | ax25-tools | >= 0 < 0.0.8-13.2 | 0.0.8-13.2 |
| debian | ax25-tools | < ax25-tools 0.0.8-13.2 (bookworm) | ax25-tools 0.0.8-13.2 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux-ax25 | ax25-tools | < 0.0.8-13 | 0.0.8-13 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mrq3-m48q-67j2: The AX
ghsa_unreviewed·2022-04-22
CVE-2011-2910 [HIGH] CWE-269 GHSA-mrq3-m48q-67j2: The AX
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
OSV
CVE-2011-2910: The AX
osv·2019-11-15·CVSS 6.7
CVE-2011-2910 [MEDIUM] CVE-2011-2910: The AX
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
Debian
CVE-2011-2910: ax25-tools - The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return...
vendor_debian·2011·CVSS 6.7
CVE-2011-2910 [MEDIUM] CVE-2011-2910: ax25-tools - The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return...
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
Scope: local
bookworm: resolved (fixed in 0.0.8-13.2)
bullseye: resolved (fixed in 0.0.8-13.2)
forky: resolved (fixed in 0.0.8-13.2)
sid: resolved (fixed in 0.0.8-13.2)
trixie: resolved (fixed in 0.0.8-13.2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2910 ax25-tools: possible privilege escalation due to failure to check for s*id return values [fedora-all]
bugzilla·2011-08-15·CVSS 6.7
CVE-2011-2910 [MEDIUM] CVE-2011-2910 ax25-tools: possible privilege escalation due to failure to check for s*id return values [fedora-all]
CVE-2011-2910 ax25-tools: possible privilege escalation due to failure to check for s*id return values [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=730783
Bugzilla
CVE-2011-2910 ax25-tools: possible privilege escalation due to failure to check for s*id return values
bugzilla·2011-08-15·CVSS 6.7
CVE-2011-2910 [MEDIUM] CVE-2011-2910 ax25-tools: possible privilege escalation due to failure to check for s*id return values
CVE-2011-2910 ax25-tools: possible privilege escalation due to failure to check for s*id return values
Dan Rosenberg reported [1] that ax25d does not check the return value of a setuid call responsible for dropping privileges. If the setuid call failed, the daemon would continue to run with root privileges.
This has not yet been corrected upstream [2].
[1] http://www.openwall.com/lists/oss-security/2011/08/10/3
[2] http://www.linux-ax25.org/cvsweb/ax25-tools/ax25/ax25d.c
Discussion:
Created ax25-tools tracking bugs for this issue
Affects: fedora-all [bug 730784]
---
A few hours ago Thomas Osterried has checked in a fix for CVE-2011-2910 into linux-ax25.org's CVS archive, see https://www.linux-ax25.org/wiki/CVS for CVS instructions and how to build. No new release tarballs have been
https://access.redhat.com/security/cve/cve-2011-2910https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2910https://security-tracker.debian.org/tracker/CVE-2011-2910https://access.redhat.com/security/cve/cve-2011-2910https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2910https://security-tracker.debian.org/tracker/CVE-2011-2910
2019-11-15
Published