Privilege Escalation in AX.25 Daemon (ax25d)

Privilege Escalation in AX.25 Daemon (ax25d)

CVE-2011-2910 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.

Learn more about our Web Application Penetration Testing UK.