Vulnerabilities > CVE-2001-0087 - Unspecified vulnerability in Michael Glickman Itetris 1.6.1/1.6.2

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
michael-glickman
exploit available

Summary

itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.

Vulnerable Configurations

Part Description Count
Application
Michael_Glickman
2

Exploit-Db

descriptionItetris 1.6.1/1.6.2 Privileged Arbitrary Command Execution Vulnerability. CVE-2001-0087. Local exploit for linux platform
idEDB-ID:20517
last seen2016-02-02
modified2000-12-19
published2000-12-19
reporterV9
sourcehttps://www.exploit-db.com/download/20517/
titleItetris 1.6.1/1.6.2 - Privileged Arbitrary Command Execution Vulnerability