CVE-2001-0087

itetris/xitetris <1.6.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.

Exploits (1)

exploitdb WORKING POC VERIFIED
by V9 · clocallinux
https://www.exploit-db.com/exploits/20517

Scores

EPSS 0.0014
EPSS Percentile 33.6%

Details

Status published
Products (2)
michael_glickman/itetris 1.6.1
michael_glickman/itetris 1.6.2
Published Feb 12, 2001
Tracked Since Feb 18, 2026