Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2004-1235

EPSS 0.08% · P24
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2004-1235

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux Kernel uselib()特权提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux Kernel是开放源代码操作系统Linux的内核。 Linux二进制格式装载器(binary format loaders)uselib()函数存在缺陷,本地攻击者可以利用这个漏洞获得root用户权限。 Linux内核提供二进制格式装载器层来装载不同格式的程序如ELF或者a.out或其他的,内核也提供sys_uselib()函数装载对应的二进制程序。从binfmt_elf.c文件中对load_elf_library()的uselib函数分析,在对库的BRK段(VMA)处理上存在问题,此段通过c
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2004-1235

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-1235

登录查看更多情报信息。

Same Patch Batch · n/a · 2005-01-20 · 8 CVEs total

CVE-2004-0812Linux Kernel AMD64/EM64T "TSS限制"本地特权提升漏洞
CVE-2004-1237Red Hat Enterprise Linux内核审核子系统本地拒绝服务漏洞
CVE-2005-0003Linux内核64位ELF支持本地拒绝服务漏洞
CVE-2005-0004Oracle MySQL 后置链接漏洞
CVE-2005-0081MySQL MaxDB WebAgent畸形头域请求拒绝服务漏洞
CVE-2005-0082MySQL MaxDB WebAgent无效参数处理拒绝服务漏洞
CVE-2005-0124Linux Kernel Coda_Pioctl本地缓冲区溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2004-1235

No comments yet


Leave a comment