CVE-2002-0499
Summary
| CVE | CVE-2002-0499 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-08-12 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.2.0 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.19 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.20 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.2.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.3.0 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.3.99 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.0 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.12 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.13 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.14 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.15 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.16 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.17 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.18 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.4.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Linux Kernel d_path() Path Truncation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Vendor Advisory |
| SecurityFocus HOME Mailing List: BugTraq | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| Linux-kernel mailing list archive 2002-13,: [PATCH] d_path() truncation | af854a3a-2127-422b-91ae-364da2661108 | www.cs.helsinki.fi | |
| ISS X-Force Database: linux-dpath-truncate-path (8634): Linux kernel d_path() function truncates path | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Vendor Advisory |
| Neohapsis Archives - VulnWatch - [VulnWatch] d_path() truncating excessive long path name vulnerability - From cliphisec.pl | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.