DEBIAN-CVE-2011-2910

Source
https://security-tracker.debian.org/tracker/CVE-2011-2910
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-2910.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2011-2910
Upstream
Published
2019-11-15T17:15:12Z
Modified
2026-09-14T07:00:40Z
Severity
  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.

References

Affected packages

Debian:12 / ax25-tools

Package

Name
ax25-tools
Purl
pkg:deb/debian/ax25-tools?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.8-13.2

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-2910.json"

Debian:13 / ax25-tools

Package

Name
ax25-tools
Purl
pkg:deb/debian/ax25-tools?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.8-13.2

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-2910.json"