← Back

CVE-2009-0641

nvd nist
Published: Feb 20, 2009Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.

Affected (8)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 7.0-release
Version 7.0
Version 7.0 beta_4
Version 7.0 current
Version 7.0_beta4
Version 7.0_releng
Version 7.1
Version 7.1 rc1

References (10)

Timeline

No history available yet.