CVE-2004-1235

Published Apr 14, 2005

Last updated 8 days ago

Overview

Description
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
Source
cve@mitre.org
NVD status
Modified
Products
mn100, network_routing, converged_communications_server, s8710, modular_messaging_message_storage_server, linux_kernel, mandrake_linux, mandrake_linux_corporate_server, enterprise_linux, enterprise_linux_desktop, fedora_core, linux, suse_linux, ubuntu_linux, intuity_audix, mandrake_multi_network_firewall, s8300, s8500, s8700, linux

Risk scores

CVSS 2.0

Type
Primary
Base score
6.2
Impact score
10
Exploitability score
1.9
Vector string
AV:L/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.