Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:091: cdrecord Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the cdrecord package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:091 (cdrecord).
Max Vozeler found that the cdrecord program, which is suid root, fails to drop
euid=0 when it exec()s a program specified by the user through the $RSH
environment variable. This can be abused by a local attacker to obtain root
The updated packages are patched to fix the vulnerability.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:091
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.