CVE-2004-1235
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
- Affected products
- Debian, Linux Kernel, Red Hat
- Avaya mn100
- All versions
- Avaya Network Routing
- All versions
- Avaya Converged Communications Server
- = 2.0
- Avaya s8710
- = r2.0.0, r2.0.1
- Avaya Modular Messaging Message Storage Server
- = 1.1, 2.0
- Linux Linux Kernel
- = 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, 2.4.9, 2.4.10, 2.4.11, 2.4.12, 2.4.13, 2.4.14, 2.4.15, 2.4.16, 2.4.17, 2.4.18, 2.4.19, 2.4.20, 2.4.21, 2.4.22, 2.4.23, 2.4.23_ow2, 2.4.24, 2.4.24_ow1, 2.4.25, 2.4.26, 2.4.27, 2.4.28, 2.4.29, 2.6.0
- Fix
- Available
- CVSS 2.0
- 6.2 MEDIUM
- EPSS
- 2.9% (86th percentile)
- NVD status
- Modified
- Published
- 2005-01-20
CVE-2004-1235 at NVD
5 known exploits for CVE-2004-1235
Proof-of-concept code and exploit modules indexed by Sploitus