7.2
CVSSv2

CVE-2004-1337

Published: 23/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu realtime linux security module 0.8.7

conectiva linux 10.0

ubuntu ubuntu linux 4.1

Vendor Advisories

Paul Starzetz discovered a race condition in the ELF library and aout binary format loaders, which can be locally exploited in several different ways to gain root privileges (CAN-2004-1235) ...