Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2003:058-1: cdrecord


Vulnerability Assessment Details

MDKSA-2003:058-1: cdrecord

Vulnerability Assessment Summary
Check for the version of the cdrecord package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2003:058-1 (cdrecord).


A vulnerability in cdrecord was discovered that can be used to obtain root
access because Mandrake Linux ships with the cdrecord binary suid root and sgid
cdwriter.
Updated packages are provided that fix this vulnerability. You may also elect to
remove the suid and sgid bits from cdrecord manually, which can be done by
executing, as root:
chmod ug-s /usr/bin/cdrecord
This is not required to protect yourself from this particular vulnerability,
however.
Update:
Two additional format string problems were discovered by Olaf Kirch and an
updated patch has been applied to fix those problems as well.


Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:058-1
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors


Keyrah V3 for Commodore 64, Amiga 1200 600 500 - Includes C64 Side Panel picture

Keyrah V3 for Commodore 64, Amiga 1200 600 500 - Includes C64 Side Panel

$75.00



GVP G-Force 040 Combo Rev 6 Accelerator Card for Amiga A2000 33MHz 68040 w/ 16MB picture

GVP G-Force 040 Combo Rev 6 Accelerator Card for Amiga A2000 33MHz 68040 w/ 16MB

$799.00



Vintage Commodore Amiga 500 Computer Keyboard Model A500 Sold As Is picture

Vintage Commodore Amiga 500 Computer Keyboard Model A500 Sold As Is

$199.99



Vintage Commodore Amiga Computer Only BR99YB-1000 (partly Tested/read) picture

Vintage Commodore Amiga Computer Only BR99YB-1000 (partly Tested/read)

$499.99



Commodore Amiga 4000 desktop computer picture

Commodore Amiga 4000 desktop computer

$2800.00



Commodore Amiga 500 Box PAL (UK) Player All Set Tested Red Eye Batman picture

Commodore Amiga 500 Box PAL (UK) Player All Set Tested Red Eye Batman

$595.00



Commodore Amiga 1200 Recapped NTSC 68030 TF1230 64 MB A1200.NET new case keycaps picture

Commodore Amiga 1200 Recapped NTSC 68030 TF1230 64 MB A1200.NET new case keycaps

$1399.99



Commodore Amiga 500 Box PAL (UK) Player All Set Tested Certified 2022 picture

Commodore Amiga 500 Box PAL (UK) Player All Set Tested Certified 2022

$495.00



pi1541 Disk Emulator for Commodore -  picture

pi1541 Disk Emulator for Commodore -

$38.95



Amiga Midi Master A500/2000 picture

Amiga Midi Master A500/2000

$50.00



Discussions

No Discussions have been posted on this vulnerability.