Vulnerabilities > Cdrtools > Cdrecord > 1.11
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-12-31 | CVE-2004-0806 | Unspecified vulnerability in Cdrtools Cdrecord 1.11/2.0 cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges. | 7.2 |
2003-06-16 | CVE-2003-0289 | Unspecified vulnerability in Cdrtools Cdrecord 1.11/2.0 Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter. | 7.2 |