Skip to main content

Vendor archive

cdrtools CVEs

Beta · best-effort

4 CVEs tagged to vendor cdrtools0 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2005-0866

Published May 2, 2005

cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0806

Published Dec 31, 2004

cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, w…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0655

Published Aug 27, 2003

rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as a command line argument, which is modi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0289

Published Jun 16, 2003

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1