VendorsCdrtoolscdrecord2.0
Vulnerabilities

Cdrtools Cdrecord 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2004-0806
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.
Published 2004-09-14 · Modified
7.22 PoCEPSS 0.017
CVE-2003-0289
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.
Published 2003-05-14 · Modified
7.22 PoCEPSS 0.011