CVE Vulnerabilities

CVE-2004-0806

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
CdrecordCdrtools1.11 (including)1.11 (including)
CdrecordCdrtools2.0 (including)2.0 (including)
Red Hat Desktop version 3RedHat*
Red Hat Enterprise Linux AS version 3RedHat*
Red Hat Enterprise Linux ES version 3RedHat*
Red Hat Enterprise Linux WS version 3RedHat*
CdrkitUbuntudevel*
CdrkitUbuntufeisty*

References