RSS   Vulnerabilities for 'Cdrecord'   RSS

2005-05-02
 
CVE-2005-0866

CWE-Other
 

 
cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

 
2004-12-31
 
CVE-2004-0806

 

 
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.

 
2003-06-16
 
CVE-2003-0289

 

 
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

 

 >>> Vendor: Cdrtools 2 Products
Cdrecord
Cdrtools


Copyright 2024, cxsecurity.com

 

Back to Top