vendor:
Mandrake Linux
by:
noir
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Mandrake Linux
Affected Version From: Mandrake 7.0
Affected Version To: Mandrake 7.0
Patch Exists: NO
Related CWE: N/A
CPE: o:mandrake:mandrake_linux:7.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Intel Linux
2001
Linux cdrecorder Binary Buffer Overflow Vulnerability
The linux cdrecorder binary is vulnerable to a locally exploitable buffer overflow attack. When installed in a Mandrake 7.0 linux distribution, it is by default setgid 'cdburner' (which is a group, gid: 80, that is created for the application). The overflow condition is the result of no bounds checking on the 'dev=' argument passed to cdburner at execution time. This vulnerability can be exploited to execute arbitrary commands with egid 'cdburner'.
Mitigation:
The user should ensure that the cdrecorder binary is not installed with setgid privileges.