The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/264117 | Vendor Advisory |
http://www.securityfocus.com/bid/4367 | Exploit Vendor Advisory |
http://www.iss.net/security_center/static/8634.php | Vendor Advisory |
http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html | |
http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-08-11 21:00
Updated : 2008-09-05 13:28
NVD link : CVE-2002-0499
Mitre link : CVE-2002-0499
JSON object : View
CWE
Products Affected
linux
- linux_kernel