PT-2004-1051 · Red Hat · Cdrecord+6

Zinx Verituse

·

Publicado

2004-09-24

·

Atualizado

2017-10-11

·

CVE-2004-0813

CVSS v2.0

3.4

Baixa

VetorAV:L/AC:H/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ide-cd (affected versions not specified) cdrecord versions 2.01.0.a32 cdrtools versions 2.01.0.a32 pam versions 0.75 pam-devel versions 0.75 cdrecord-devel versions 2.01.0.a32
Description The issue allows local users to bypass read-only access and perform unauthorized write and erase operations. Multiple vulnerabilities in the cdrecord, cdrtools, pam, pam-devel, and cdrecord-devel packages of Red Hat Enterprise Linux can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally by an attacker who has passed the authentication procedure.
Recommendations For ide-cd, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For cdrecord versions 2.01.0.a32, consider restricting access to the SG IO functionality until a patch is available. For cdrtools versions 2.01.0.a32, avoid using the vulnerable package until the issue is resolved. For pam versions 0.75, restrict access to the vulnerable module to minimize the risk of exploitation. For pam-devel versions 0.75, consider disabling the vulnerable functions until a patch is available. For cdrecord-devel versions 2.01.0.a32, restrict access to the vulnerable package to minimize the risk of exploitation.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-05972
BDU:2015-05973
BDU:2015-05974
BDU:2015-06021
BDU:2015-06024
CVE-2004-0813
RHSA-2007:0465

Produtos afetados

Red Hat
Cdrecord
Cdrecord-Devel
Cdrtools
Ide-Cd
Pam
Pam-Devel