Record summary

CVE-2003-0289 has a selected CVSS score of 7.2; EIP currently links 2 catalogued exploits.

Description

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBCDRTools CDRecord 1.11/2.0 - Devname Format StringExploitDB exploitby CMNNot analyzed1 file
ExploitDB

PoC details
ExploitDBCDRTools CDRecord 2.0 (Mandrake / Slackware) - Local Privilege EscalationExploitDB exploitby anonymousNot analyzed1 file
ExploitDB

PoC details

References

8