CNCVE编号:CNCVE-20010087 CVE编号:CAN-2001-0087 安全级别:高 漏洞中文描述: itetris/xitetris 1.6.2 及其早期版本使用PATH环境变量来查找和执行gunzip程序,这允许本地用户通过改变他们的PATH使得它指向一个恶意gunzip程序来获得root权限。 漏洞英文描述: itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program. 漏洞参考: BUGTRAQ:20001219 itetris