VulnerabilityModified
CVE-2011-2910
The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
MEDIUM 6.7EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- linux-ax25/ax25-tools · debian/debian linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/cve-2011-2910Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2910Issue Tracking, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-2910Third Party Advisory
- https://access.redhat.com/security/cve/cve-2011-2910Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2910Issue Tracking, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-2910Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.