Vulnerabilities > CVE-2003-0289 - Unspecified vulnerability in Cdrtools Cdrecord 1.11/2.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description CDRTools CDRecord 1.11/2.0 Devname Format String Vulnerability. CVE-2003-0289. Local exploit for linux platform id EDB-ID:22594 last seen 2016-02-02 modified 2003-05-13 published 2003-05-13 reporter CMN source https://www.exploit-db.com/download/22594/ title CDRTools CDRecord 1.11/2.0 Devname Format String Vulnerability description CdRecord Version. CVE-2003-0289. Local exploit for linux platform id EDB-ID:31 last seen 2016-01-31 modified 2003-05-14 published 2003-05-14 reporter N/A source https://www.exploit-db.com/download/31/ title CdRecord <= 2.0 - Mandrake Local Root Exploit
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2003-058.NASL |
description | A vulnerability in cdrecord was discovered that can be used to obtain root access because Mandrake Linux ships with the cdrecord binary suid root and sgid cdwriter. Updated packages are provided that fix this vulnerability. You may also elect to remove the suid and sgid bits from cdrecord manually, which can be done by executing, as root : chmod ug-s /usr/bin/cdrecord This is not required to protect yourself from this particular vulnerability, however. Update : Two additional format string problems were discovered by Olaf Kirch and an updated patch has been applied to fix those problems as well. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14042 |
published | 2004-07-31 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14042 |
title | Mandrake Linux Security Advisory : cdrecord (MDKSA-2003:058-1) |
code |
|
References
- ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz
- ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz
- http://forums.gentoo.org/viewtopic.php?t=54904
- http://forums.gentoo.org/viewtopic.php?t=54904
- http://marc.info/?l=bugtraq&m=105285564307225&w=2
- http://marc.info/?l=bugtraq&m=105285564307225&w=2
- http://marc.info/?l=bugtraq&m=105286031812533&w=2
- http://marc.info/?l=bugtraq&m=105286031812533&w=2
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:058
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:058
- http://www.securiteam.com/exploits/5ZP0C2AAAC.html
- http://www.securiteam.com/exploits/5ZP0C2AAAC.html
- http://www.securityfocus.com/bid/7565
- http://www.securityfocus.com/bid/7565
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12007