PT-2001-1322 · Iteris · Itetris/Xitetris
Publicado
2001-02-02
·
Atualizado
2017-12-19
·
CVE-2001-0087
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
itetris/xitetris versions 1.6.2 and earlier
Description:
The issue allows local users to gain root privileges by exploiting the trust in the PATH environmental variable to find and execute the gunzip program. This can be achieved by changing the PATH so that it points to a malicious gunzip program.
Recommendations:
For itetris/xitetris versions 1.6.2 and earlier, consider restricting the use of the gunzip program or modifying the PATH environmental variable to prevent it from pointing to malicious programs until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Itetris/Xitetris