itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2001-0087 | itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T04:06:55.354Z
Reserved: 2001-02-01T00:00:00
Link: CVE-2001-0087
No data.
Status : Deferred
Published: 2001-02-12T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2001-0087
No data.
OpenCVE Enrichment
No data.
EUVD