Skip to main content

Vendor/product archive

cdrtools / cdrecord CVEs

Beta · best-effort

3 CVEs tagged to cdrtools / cdrecord0 Critical, 2 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2005-0866

Published May 2, 2005

cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0806

Published Dec 31, 2004

cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, w…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0289

Published Jun 16, 2003

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1