CVE Vulnerabilities

CVE-2004-0806

Published: Dec 31, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.

Affected Software

Name Vendor Start Version End Version
Cdrecord Cdrtools 1.11 (including) 1.11 (including)
Cdrecord Cdrtools 2.0 (including) 2.0 (including)
Red Hat Desktop version 3 RedHat *
Red Hat Enterprise Linux AS version 3 RedHat *
Red Hat Enterprise Linux ES version 3 RedHat *
Red Hat Enterprise Linux WS version 3 RedHat *
Cdrkit Ubuntu devel *
Cdrkit Ubuntu feisty *

References