积极预防 及时发现
快速响应 力保恢复
itetris/xitetris 1.6.2 及其早期版本使用PATH环境变量来查找和执行gunzi...
发布时间:2001-02-12 信息来源:管理员

CNCVE编号:CNCVE-20010087 CVE编号:CAN-2001-0087 安全级别:高 漏洞中文描述: itetris/xitetris 1.6.2 及其早期版本使用PATH环境变量来查找和执行gunzip程序,这允许本地用户通过改变他们的PATH使得它指向一个恶意gunzip程序来获得root权限。 漏洞英文描述: itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program. 漏洞参考: BUGTRAQ:20001219 itetris local root exploit (system()+../ protection) BID:2139 XF:itetris-svgalib-path 系统类型:其他 漏洞类型:环境错误