PT-2001-1322 · Iteris · Itetris/Xitetris
Published
2001-02-02
·
Updated
2017-12-19
·
CVE-2001-0087
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
itetris/xitetris versions 1.6.2 and earlier
Description:
The issue allows local users to gain root privileges by exploiting the trust in the PATH environmental variable to find and execute the gunzip program. This can be achieved by changing the PATH so that it points to a malicious gunzip program.
Recommendations:
For itetris/xitetris versions 1.6.2 and earlier, consider restricting the use of the gunzip program or modifying the PATH environmental variable to prevent it from pointing to malicious programs until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Itetris/Xitetris