Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Gentoo: 200305-06 Moderate: cdrtools Privilege Escalation

gentoo
Calendar Grey May 17, 2003
Dist Gentoo Esm H88
GENTOO LINUX SECURITY ALERT 202305-09 regarding cdrtools vulnerability allowing elevated privileges
A vulnerability in cdrecord that could lead to a root compromise was discovered

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200305-06
- - ---------------------------------------------------------------------
		    =cdrtools-1.11.39-r1

- - ---------------------------------------------------------------------
Cdrecord isn't installed setuid root by default in Gentoo.
Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=105285351304781&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running app-cdr/cdrtools upgrade to one of the following versions: for users running xcdroast: cdrtools-1.11.33-r1 for sparc users: cdrtools-1.11.39-r1 for everyone else: cdrtools-2.01_alpha14
emerge sync emerge \=app-cdr/ emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

PACKAGE : cdrtools
SUMMARY : privelige escalation
DATE : 2003-05-17 14:07 UTC
EXPLOIT : local
VERSIONS AFFECTED : =cdrtools-2.01_alpha14, =cdrtools-1.11.33-r1,
CVE : CAN-2003-0289

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here