CVE

Id
4891  
CVE No.
CVE-2002-0499  
Status
Candidate  
Description
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.  
Phase
Proposed (20020611)  
Votes
ACCEPT(3) Cole, Foat, Frech | NOOP(3) Armstrong, Cox, Wall | REVIEWING(1) Christey  
Comments
CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | CHANGE> [Cox changed vote from ACCEPT to NOOP] | Christey> Need to investigate this more... is it the responsibility | of the kernel to address this, or the application | programmer?