Name | CVE-2004-1235 |
Description | Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1067-1, DSA-1069-1, DSA-1070-1, DSA-1082-1 |
Debian Bugs | 289202, 289708, 291053 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
kernel-image-sparc-2.4 | source | woody | 26woody1 | DSA-1070-1 | ||
kernel-patch-2.4.19-mips | source | woody | 2.4.19-0.020911.1.woody5 | DSA-1070-1 | ||
kernel-source-2.4.16 | source | woody | 2.4.16-1woody2 | DSA-1067-1 | ||
kernel-source-2.4.17 | source | woody | 2.4.17-1woody4 | DSA-1082-1 | ||
kernel-source-2.4.18 | source | woody | 2.4.18-14.4 | DSA-1069-1 | ||
kernel-source-2.4.19 | source | woody | 2.4.19-4.woody3 | DSA-1070-1 | ||
kernel-source-2.4.27 | source | (unstable) | 2.4.27-8 | high | 289202, 289708, 291053 | |
linux-2.6 | source | (unstable) | (not affected) |
- linux-2.6 <not-affected> (Fixed before upload into archive)