Max Vozeler found that the cdrecord program, which is suid root, fails to drop euid=0 when it exec()s a program specified by the user through the $RSH environment variable. This can be abused by a local attacker to obtain root privileges. The following exploit code can be used to test your system for the mentioned vulnerability.
Credit:
The information has been provided by newbug Tseng.