Описание
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 0.0.8-13.2 |
| hardy | ignored | end of life |
| lucid | ignored | end of life |
| maverick | ignored | end of life |
| natty | ignored | end of life |
| oneiric | ignored | end of life |
| precise | not-affected | 0.0.8-13.2 |
| quantal | not-affected | 0.0.8-13.2 |
| raring | not-affected | 0.0.8-13.2 |
| saucy | not-affected | 0.0.8-13.2 |
Показывать по
7.2 High
CVSS2
6.7 Medium
CVSS3
Связанные уязвимости
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check ...
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.
7.2 High
CVSS2
6.7 Medium
CVSS3