CVE-2009-0641
Published Feb 20, 2009
Last updated 7 years ago
Overview
- Description
- sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-16
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47E0A416-733A-4616-AE08-150D67FCEA70" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.0:beta_4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CDFA5AA9-E73F-448D-9754-41AF9AECB93A" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.0:current:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4E775BA-6DC1-4006-83A4-D30EA57417FC" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.0-release:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC290462-4364-464F-8CE9-6F5E5BE6F246" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.0_beta4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F06B831E-D8F2-4380-B279-559CE103210F" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.0_releng:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3ACC9072-4A33-4F1F-B790-2F9D5A52F71B" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "803EFA9F-B7CB-4511-B1C1-381170CA9A23" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.1:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52DBF406-9C77-4DDA-AB7D-40FAE40023D0" } ], "operator": "OR" } ] } ]