Cdrdao records audio or data CD-Rs in disk-at-once (DAO) mode based on a textual description of the CD contents. There are several security-related bugs in the distributed Debian (SID) Package of CDRDAO. /usr/bin/cdrdao is setuid-root by default allowing gaining of elevated privileges.
Credit:
The information has been provided by Jens Steube.
One of the feature cdrdao has is the ability to write a configuration file (Written to "$HOME/.cdrdao"). Since it is written by the root user and not as the user who starts cdrdao, it is possible to include data on the written configfile thus it is possible to gain root via a symlink-attack on $HOME/.cdrdao.