CVE Vulnerabilities

CVE-2004-0806

Published: Dec 31, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.

Affected Software

Name Vendor Start Version End Version
Cdrecord Cdrtools 1.11 1.11
Cdrecord Cdrtools 2.0 2.0
Red Hat Enterprise Linux 3 RedHat cdrtools *
Cdrkit Ubuntu devel *
Cdrkit Ubuntu feisty *

References