VYPR
Unrated severityNVD Advisory· Published Feb 12, 2001· Updated Apr 16, 2026

CVE-2001-0087

CVE-2001-0087

Description

itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.

Affected products

2
  • cpe:2.3:a:michael_glickman:itetris:1.6.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:michael_glickman:itetris:1.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:michael_glickman:itetris:1.6.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.