Search

published date: April 14, 2005

CVE-2004-1235 : Race Condition Vulnerability

Description

Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

Product(s):

  • Avaya Intuity Audix LX
  • Avaya MN100
  • Avaya Network Routing
  • MandrakeSoft Mandrake Multi Network Firewall 8.2

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-1235, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-1235 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?