Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CDRTools RSH环境变量权限提升漏洞
Vulnerability Description
CDRTools是一款基于Linux的刻录工具。 CDRecord对RSH环境变量处理不正确,本地攻击者可以利用这个漏洞进行特权提升攻击。 由于CDRecord执行RSH环境变量指定的应用程序时不正确的实现安全控制,攻击者可以利用环境变量获得超级用户特权。
CVSS Information
N/A
Vulnerability Type
N/A