The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html | |
http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html | |
http://www.iss.net/security_center/static/8634.php | Vendor Advisory |
http://www.securityfocus.com/archive/1/264117 | Vendor Advisory |
http://www.securityfocus.com/bid/4367 | Exploit Vendor Advisory |
http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html | |
http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html | |
http://www.iss.net/security_center/static/8634.php | Vendor Advisory |
http://www.securityfocus.com/archive/1/264117 | Vendor Advisory |
http://www.securityfocus.com/bid/4367 | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html - | |
References | () http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html - | |
References | () http://www.iss.net/security_center/static/8634.php - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/264117 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/4367 - Exploit, Vendor Advisory |
Information
Published : 2002-08-12 04:00
Updated : 2024-11-20 23:39
NVD link : CVE-2002-0499
Mitre link : CVE-2002-0499
CVE.ORG link : CVE-2002-0499
JSON object : View
Products Affected
linux
- linux_kernel
CWE