200305-06Vendor advisory
http://forums.gentoo.org/viewtopic.php?t=54904 CVE-2003-0289
CDRTools CDRecord 1.11/2.0 - Devname Format String
Record summary
CVE-2003-0289 has a selected CVSS score of 7.2; EIP currently links 2 catalogued exploits.
Description
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBCDRTools CDRecord 1.11/2.0 - Devname Format StringExploitDB exploitby CMNNot analyzed1 file
ExploitDBCDRTools CDRecord 2.0 (Mandrake / Slackware) - Local Privilege EscalationExploitDB exploitby anonymousNot analyzed1 file
References
820030513 cdrtools2.0 Format String Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=105285564307225&w=2 20030513 Cdrecord_local_root_exploit.mailing list
http://marc.info/?l=bugtraq&m=105286031812533&w=2 MDKSA-2003:058Vendor advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2003:058 securiteam.com
http://www.securiteam.com/exploits/5ZP0C2AAAC.html 7565vdb entry
http://www.securityfocus.com/bid/7565 cdrtools-scsiopen-format-string(12007)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/12007 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0289