Skip to main content

CVE-2004-0806

7.2
CVSS v2.0 Base Score
1.73%
LOW RiskEPSS (75th percentile)
NVD-CWE-Other

cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.

Published: 12/31/2004
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

1.73%LOW Exploitation Risk
75th percentile

This vulnerability has a 1.73% probability of being exploited in the next 30 days, ranking higher than 75% of all scored CVEs.

CWE Classification

NVD-CWE-Other