VulnerabilityModified
CVE-2002-0499
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.
LOW 2.1EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html
- http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html
- http://www.iss.net/security_center/static/8634.phpVendor Advisory
- http://www.securityfocus.com/archive/1/264117Vendor Advisory
- http://www.securityfocus.com/bid/4367Exploit, Vendor Advisory
- http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html
- http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html
- http://www.iss.net/security_center/static/8634.phpVendor Advisory
- http://www.securityfocus.com/archive/1/264117Vendor Advisory
- http://www.securityfocus.com/bid/4367Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.