CVE
- Id
- 9234
- CVE No.
- CVE-2004-0806
- Status
- Candidate
- Description
- cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.
- Phase
- Assigned (20040825)
- Votes
- None (candidate not yet proposed)
- Comments