Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-1235

9 documents7 sources
Severity
6.2MEDIUM
EPSS
0.1%
top 75.60%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 14
Latest updateApr 29

Description

Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages15 packages

NVDlinux/linux_kernel44 versions+43
NVDredhat/linux7.3, 9.0+1
NVDconectiva/linux10.0
NVDsuse/suse_linux7 versions+6
NVDmandrakesoft/mandrake_linux10.0, 10.1, 9.2+2

Also affects: Ubuntu Linux 4.1, Enterprise Linux 3.0, 4.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pxmj-v2v3-474h: Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 22022-04-29
CVEList
CVE-2004-1235: Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 22005-01-20

💥Exploits & PoCs

3
Exploit-DB
Linux Kernel 2.4.x/2.6.x - 'uselib()' Local Privilege Escalation (3)2005-03-22
Exploit-DB
Linux Kernel 2.4 - 'uselib()' Local Privilege Escalation (2)2005-01-27
Exploit-DB
Linux Kernel 2.4.29-rc2 - 'uselib()' Local Privilege Escalation (1)2005-01-07

📋Vendor Advisories

2
Ubuntu
Linux kernel vulnerabilities2005-01-09
Red Hat
security flaw2005-01-06

💬Community

1
Bugzilla
CVE-2004-1235 security flaw2018-08-16