peter bassill · operator
$ cve CVE-2004-1235 JSON

CVE-2004-1235 EXPLOIT

6.2
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 86)

Patch early

A public exploit exists.

Description

Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

Scoring

CVSS6.2 (MEDIUM, v2.0)
VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
EPSS2.89% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2005-04-14
Last modified2026-06-16

Affected (20)

VendorProduct
avayaconverged communications server
avayaintuity audix
avayamn100
avayamodular messaging message storage server
avayanetwork routing
avayas8300
avayas8500
avayas8700
avayas8710
conectivalinux
linuxlinux kernel
mandrakesoftmandrake linux
mandrakesoftmandrake linux corporate server
mandrakesoftmandrake multi network firewall
redhatenterprise linux
redhatenterprise linux desktop
redhatfedora core
redhatlinux
susesuse linux
ubuntuubuntu linux

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD