VulnerabilityModified
CVE-2004-1235
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
MEDIUM 6.2EPSS 2.89%
Does this matter?
Lower severity and a low EPSS score (2.89%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
- CVSS 2.0
- 6.2 MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 2.89% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- avaya/mn100 · avaya/network routing · avaya/converged communications server · avaya/s8710 · avaya/modular messaging message storage server · linux/linux kernel · mandrakesoft/mandrake linux · mandrakesoft/mandrake linux corporate server · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/fedora core · redhat/linux · suse/suse linux · ubuntu/ubuntu linux · avaya/intuity audix · mandrakesoft/mandrake multi network firewall · avaya/s8300 · avaya/s8500 · avaya/s8700 · conectiva/linux
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000930
- http://isec.pl/vulnerabilities/isec-0021-uselib.txt
- http://marc.info/?l=bugtraq&m=110512575901427&w=2
- http://secunia.com/advisories/20162
- http://secunia.com/advisories/20163
- http://secunia.com/advisories/20202
- http://secunia.com/advisories/20338
- http://www.debian.org/security/2006/dsa-1067
- http://www.debian.org/security/2006/dsa-1069
- http://www.debian.org/security/2006/dsa-1070
- http://www.debian.org/security/2006/dsa-1082
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:022
- http://www.novell.com/linux/security/advisories/2005_01_sr.html
- http://www.redhat.com/support/errata/RHSA-2005-016.html
- http://www.redhat.com/support/errata/RHSA-2005-017.html
- http://www.redhat.com/support/errata/RHSA-2005-043.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-092.html
- http://www.securityfocus.com/advisories/7804
- http://www.securityfocus.com/advisories/7805
- http://www.securityfocus.com/advisories/7806
- http://www.securityfocus.com/bid/12190Exploit, Patch, Vendor Advisory
- http://www.trustix.org/errata/2005/0001/
- https://bugzilla.fedora.us/show_bug.cgi?id=2336
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18800
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9567
- http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000930
- http://isec.pl/vulnerabilities/isec-0021-uselib.txt
- http://marc.info/?l=bugtraq&m=110512575901427&w=2
- http://secunia.com/advisories/20162
- http://secunia.com/advisories/20163
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.