7.2
CVSSv2

CVE-2000-0231

Published: 16/03/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

suse suse linux 6.3

halloween halloween linux 4.0

suse suse linux 6.1

suse suse linux 6.0

suse suse linux 6.2

Exploits

source: wwwsecurityfocuscom/bid/1061/info A vulnerability exists in the kreatecd program for Linux This program is a graphical front end to the cdrecord program, and is installed setuid root This program will blindly trust the configuration of the path to cdrecord, as specified by the user This means that arbitrary programs can be exec ...