CVE-2004-1235 EXPLOIT
6.2
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 86)
Patch early
A public exploit exists.
Description
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
Scoring
| CVSS | 6.2 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
| EPSS | 2.89% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-04-14 |
| Last modified | 2026-06-16 |
Affected (20)
| Vendor | Product |
|---|---|
| avaya | converged communications server |
| avaya | intuity audix |
| avaya | mn100 |
| avaya | modular messaging message storage server |
| avaya | network routing |
| avaya | s8300 |
| avaya | s8500 |
| avaya | s8700 |
| avaya | s8710 |
| conectiva | linux |
| linux | linux kernel |
| mandrakesoft | mandrake linux |
| mandrakesoft | mandrake linux corporate server |
| mandrakesoft | mandrake multi network firewall |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | fedora core |
| redhat | linux |
| suse | suse linux |
| ubuntu | ubuntu linux |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel 2.4.x/2.6.x - 'uselib()' Local Privilege Escalation (3) | 2005-03-22 |
| exploit-db | Linux Kernel 2.4 - 'uselib()' Local Privilege Escalation (2) | 2005-01-27 |
| exploit-db | Linux Kernel 2.4.29-rc2 - 'uselib()' Local Privilege Escalation (1) | 2005-01-07 |
References
- http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000930
- http://isec.pl/vulnerabilities/isec-0021-uselib.txt
- http://marc.info/?l=bugtraq&m=110512575901427&w=2
- http://secunia.com/advisories/20162
- http://secunia.com/advisories/20163
- http://secunia.com/advisories/20202
- http://secunia.com/advisories/20338
- http://www.debian.org/security/2006/dsa-1067
- http://www.debian.org/security/2006/dsa-1069
- http://www.debian.org/security/2006/dsa-1070
- http://www.debian.org/security/2006/dsa-1082
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:022
- http://www.novell.com/linux/security/advisories/2005_01_sr.html
- http://www.redhat.com/support/errata/RHSA-2005-016.html
- http://www.redhat.com/support/errata/RHSA-2005-017.html
- http://www.redhat.com/support/errata/RHSA-2005-043.html
- http://www.redhat.com/support/errata/RHSA-2005-092.html
- http://www.securityfocus.com/advisories/7804
- http://www.securityfocus.com/advisories/7805
- http://www.securityfocus.com/advisories/7806
→ the Explorer · watch your stack · NVD