LWN.net Logo

cdrdao: local root vulnerability

Package(s):cdrdao CVE #(s):CAN-2002-0137 CAN-2002-0138
Created:May 19, 2005 Updated:May 25, 2005
Description: The cdrdao CD burning utility has two vulnerabilities. Local users can use the show-data command to read arbitrary files, and local users can overwrite arbitrary files via a symlink attack on the ~/.cdrdao config file. This can be exploited to gain root privileges.
Alerts:
Mandriva MDKSA-2005:089 2005-05-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds