CVE-2004-0806

Publication date 31 December 2004

Last updated 17 July 2025


Ubuntu priority

Description

cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.

Status

Package Ubuntu Release Status
cdrkit 7.04 feisty
Fixed 1.1.2-1
6.10 edgy Not in release
6.06 LTS dapper Not in release
cdrtools 7.04 feisty Not in release
6.10 edgy
Not affected
6.06 LTS dapper
Not affected


Access our resources on patching vulnerabilities