CVE-2004-1070
published 2005-01-10CVE-2004-1070: The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return…
PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.51%
40.0th percentile
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-92gj-7w52-q2cw: The load_elf_binary function in the binfmt_elf loader (binfmt_elf
ghsa_unreviewed·2022-05-03
CVE-2004-1070 [HIGH] GHSA-92gj-7w52-q2cw: The load_elf_binary function in the binfmt_elf loader (binfmt_elf
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
Red Hat
security flaw
vendor_redhat·2004-11-10·CVSS 7.2
CVE-2004-1070 [HIGH] security flaw
security flaw
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-1070 security flaw
bugzilla·2018-08-16·CVSS 7.2
CVE-2004-1070 [HIGH] CVE-2004-1070 security flaw
CVE-2004-1070 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
Bugzilla
CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
bugzilla·2004-10-06
[MEDIUM] CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
Paul Starzetz has repoted to vendor-sec an issue in the Linux ELF
binary loader while handling setuid binaries. This could lead to
local privilege escalation.
This issue is fairly complicated, the advisory is attachment 104867
with the current patch being investigated as attachment 104868
This issue is currently embargoed with no date set.
Discussion:
moving to needinfo, as per Dave Anderson's comments in the
corresponding rhel3 bug, 134874.
---
Removing embargo.
---
Here is the CVE information for this issue.
>>20040920 binfmt_elf loader vulnerabilities
>>
>> 2.4.27 and earlier, 2.6.9 and earlier are vulnerable
>>
>> http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt
>>
>> 1&3 Mi
Bugzilla
CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
bugzilla·2004-10-06
[MEDIUM] CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
Paul Starzetz has repoted to vendor-sec an issue in the Linux ELF
binary loader while handling setuid binaries. This could lead to
local privilege escalation.
This issue is fairly complicated, the advisory is attachment 104867
with the current patch being investigated as attachment 104868
This issue is currently embargoed with no date set.
Discussion:
moving to needinfo, as per Dave Anderson's comments in the
corresponding rhel3 bug, 134874.
---
Removing embargo.
---
A patch to fix this issue has been committed to the RHEL2.1 U6 (pensacola) tree
for release 2.4.9-e.56
---
Here is the CVE information for this issue.
>>20040920 binfmt_elf loader vulnerabilities
>>
>> 2.4.27 and earlier, 2.
ftp://patches.sgi.com/support/free/security/advisories/20060402-01-Uhttp://secunia.com/advisories/19607http://secunia.com/advisories/20162http://secunia.com/advisories/20163http://secunia.com/advisories/20202http://secunia.com/advisories/20338http://www.debian.org/security/2006/dsa-1067http://www.debian.org/security/2006/dsa-1069http://www.debian.org/security/2006/dsa-1070http://www.debian.org/security/2006/dsa-1082http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2005:022http://www.redhat.com/support/errata/RHSA-2004-504.htmlhttp://www.redhat.com/support/errata/RHSA-2004-505.htmlhttp://www.redhat.com/support/errata/RHSA-2004-549.htmlhttp://www.securityfocus.com/bid/11646https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/18025https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9450ftp://patches.sgi.com/support/free/security/advisories/20060402-01-Uhttp://secunia.com/advisories/19607http://secunia.com/advisories/20162http://secunia.com/advisories/20163http://secunia.com/advisories/20202http://secunia.com/advisories/20338http://www.debian.org/security/2006/dsa-1067http://www.debian.org/security/2006/dsa-1069http://www.debian.org/security/2006/dsa-1070http://www.debian.org/security/2006/dsa-1082http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2005:022http://www.redhat.com/support/errata/RHSA-2004-504.htmlhttp://www.redhat.com/support/errata/RHSA-2004-505.htmlhttp://www.redhat.com/support/errata/RHSA-2004-549.htmlhttp://www.securityfocus.com/bid/11646https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/18025https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9450
2005-01-10
Published