MEDIUM · 6.2

CVE-2004-1235

Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by ma...

Vulnerability Description

Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

CVSS Score

6.2

MEDIUM

AV:L/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AvayaMn100All versions
AvayaNetwork RoutingAll versions
AvayaConverged Communications Server2.0
AvayaS8710r2.0.0
AvayaModular Messaging Message Storage Server1.1
LinuxLinux Kernel2.4.0
MandrakesoftMandrake Linux9.2
MandrakesoftMandrake Linux Corporate Server2.1
RedhatEnterprise Linux3.0
RedhatEnterprise Linux Desktop3.0
RedhatFedora Corecore_1.0
RedhatLinux7.3
SuseSuse Linux1.0
UbuntuUbuntu Linux4.1
AvayaIntuity AudixAll versions
MandrakesoftMandrake Multi Network Firewall8.2
AvayaS8300r2.0.0
AvayaS8500r2.0.0
AvayaS8700r2.0.0
ConectivaLinux10.0

References

FAQ

What is CVE-2004-1235?

CVE-2004-1235 is a vulnerability with a CVSS score of 6.2 (MEDIUM). Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by ma...

How severe is CVE-2004-1235?

CVE-2004-1235 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1235?

Check the references section above for vendor advisories and patch information. Affected products include: Avaya Mn100, Avaya Network Routing, Avaya Converged Communications Server, Avaya S8710, Avaya Modular Messaging Message Storage Server.