7.2
CVSSv2

CVE-2011-2910

Published: 15/11/2019 Updated: 26/11/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The AX.25 daemon (ax25d) in ax25-tools prior to 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux-ax25 ax25-tools

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #638198 CVE-2011-2910: Missing return checks Package: ax25-tools; Maintainer for ax25-tools is Debian Hamradio Maintainers <debian-hams@listsdebianorg>; Source for ax25-tools is src:ax25-tools (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Wed, 17 Au ...