Back

CVE-2003-0289

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

Published: Jun 16, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
cdrtools cdrecord 1.11
cdrtools cdrecord 2.0

GitHub Security Advisory GHSA-xp7j-9g27-rqpj

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 1.06%

Top 39% most likely to be exploited

Threat Score 29.1 / 100

Data Sources

NVD EPSS GitHub