LWN.net Logo

cdrecord: format string vulnerability

Package(s):cdrecord CVE #(s):CAN-2003-0289
Created:May 16, 2003 Updated:May 21, 2003
Description: A format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the "dev" parameter.
Alerts:
Mandrake MDKSA-2003:058-1 2003-05-21
Gentoo 200305-06 2003-05-18
Mandrake MDKSA-2003:058 2003-05-15

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds