CVE-2004-1072
published 2005-01-10CVE-2004-1072: The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL…
PriorityP421high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.56%
42.8th percentile
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2004-11-10·CVSS 7.2
CVE-2004-1072 [HIGH] security flaw
security flaw
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
GHSA
GHSA-7p9x-fr92-xwxr: The binfmt_elf loader (binfmt_elf
ghsa_unreviewed·2022-05-03
CVE-2004-1072 [HIGH] GHSA-7p9x-fr92-xwxr: The binfmt_elf loader (binfmt_elf
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-1072 security flaw
bugzilla·2018-08-16·CVSS 7.2
CVE-2004-1072 [HIGH] CVE-2004-1072 security flaw
CVE-2004-1072 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
Bugzilla
CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
bugzilla·2004-10-06
[MEDIUM] CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
Paul Starzetz has repoted to vendor-sec an issue in the Linux ELF
binary loader while handling setuid binaries. This could lead to
local privilege escalation.
This issue is fairly complicated, the advisory is attachment 104867
with the current patch being investigated as attachment 104868
This issue is currently embargoed with no date set.
Discussion:
moving to needinfo, as per Dave Anderson's comments in the
corresponding rhel3 bug, 134874.
---
Removing embargo.
---
Here is the CVE information for this issue.
>>20040920 binfmt_elf loader vulnerabilities
>>
>> 2.4.27 and earlier, 2.6.9 and earlier are vulnerable
>>
>> http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt
>>
>> 1&3 Mi
Bugzilla
CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
bugzilla·2004-10-06
[MEDIUM] CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
CAN-2004-1070 binfmt_elf loader vulnerabilities (CAN-2004-1071 CAN-2004-1072 CAN-2004-1073)
Paul Starzetz has repoted to vendor-sec an issue in the Linux ELF
binary loader while handling setuid binaries. This could lead to
local privilege escalation.
This issue is fairly complicated, the advisory is attachment 104867
with the current patch being investigated as attachment 104868
This issue is currently embargoed with no date set.
Discussion:
moving to needinfo, as per Dave Anderson's comments in the
corresponding rhel3 bug, 134874.
---
Removing embargo.
---
A patch to fix this issue has been committed to the RHEL2.1 U6 (pensacola) tree
for release 2.4.9-e.56
---
Here is the CVE information for this issue.
>>20040920 binfmt_elf loader vulnerabilities
>>
>> 2.4.27 and earlier, 2.
ftp://patches.sgi.com/support/free/security/advisories/20060402-01-Uhttp://secunia.com/advisories/19607http://secunia.com/advisories/20162http://secunia.com/advisories/20163http://secunia.com/advisories/20202http://secunia.com/advisories/20338http://www.debian.org/security/2006/dsa-1067http://www.debian.org/security/2006/dsa-1069http://www.debian.org/security/2006/dsa-1070http://www.debian.org/security/2006/dsa-1082http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2005:022http://www.redhat.com/support/errata/RHSA-2004-504.htmlhttp://www.redhat.com/support/errata/RHSA-2004-505.htmlhttp://www.redhat.com/support/errata/RHSA-2004-537.htmlhttp://www.redhat.com/support/errata/RHSA-2005-275.htmlhttp://www.securityfocus.com/bid/11646https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/18025https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11195ftp://patches.sgi.com/support/free/security/advisories/20060402-01-Uhttp://secunia.com/advisories/19607http://secunia.com/advisories/20162http://secunia.com/advisories/20163http://secunia.com/advisories/20202http://secunia.com/advisories/20338http://www.debian.org/security/2006/dsa-1067http://www.debian.org/security/2006/dsa-1069http://www.debian.org/security/2006/dsa-1070http://www.debian.org/security/2006/dsa-1082http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2005:022http://www.redhat.com/support/errata/RHSA-2004-504.htmlhttp://www.redhat.com/support/errata/RHSA-2004-505.htmlhttp://www.redhat.com/support/errata/RHSA-2004-537.htmlhttp://www.redhat.com/support/errata/RHSA-2005-275.htmlhttp://www.securityfocus.com/bid/11646https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/18025https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11195
2005-01-10
Published