CVE-2004-0806
Publication date 31 December 2004
Last updated 17 July 2025
Ubuntu priority
Description
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| cdrkit | ||
| cdrtools | ||