CVE

Id
9234  
CVE No.
CVE-2004-0806  
Status
Candidate  
Description
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.  
Phase
Assigned (20040825)  
Votes
None (candidate not yet proposed)  
Comments