Vulnerabilities > CVE-2002-0499 - Unspecified vulnerability in Linux Kernel
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN linux
exploit available
Summary
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.
Vulnerable Configurations
Exploit-Db
description | Linux Kernel 2.2.x/2.3/2.4.x d_path() Path Truncation Vulnerability. CVE-2002-0499. Local exploit for linux platform |
id | EDB-ID:21353 |
last seen | 2016-02-02 |
modified | 2002-03-26 |
published | 2002-03-26 |
reporter | cliph |
source | https://www.exploit-db.com/download/21353/ |
title | Linux Kernel 2.2.x/2.3/2.4.x d_path Path Truncation Vulnerability |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html
- http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html
- http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html
- http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html
- http://www.iss.net/security_center/static/8634.php
- http://www.iss.net/security_center/static/8634.php
- http://www.securityfocus.com/archive/1/264117
- http://www.securityfocus.com/archive/1/264117
- http://www.securityfocus.com/bid/4367
- http://www.securityfocus.com/bid/4367