CVE Vulnerabilities

CVE-2009-0641

Published: Feb 20, 2009 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 7.0 (including) 7.0 (including)
Freebsd Freebsd 7.0-beta_4 (including) 7.0-beta_4 (including)
Freebsd Freebsd 7.0-current (including) 7.0-current (including)
Freebsd Freebsd 7.0-release (including) 7.0-release (including)
Freebsd Freebsd 7.0_beta4 (including) 7.0_beta4 (including)
Freebsd Freebsd 7.0_releng (including) 7.0_releng (including)
Freebsd Freebsd 7.1 (including) 7.1 (including)
Freebsd Freebsd 7.1-rc1 (including) 7.1-rc1 (including)

References