9.3
CVSSv2

CVE-2009-0641

Published: 20/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote malicious users to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 7.1

freebsd freebsd 7.0

freebsd freebsd 7.0-release

freebsd freebsd 7.0_beta4

freebsd freebsd 7.0_releng

Exploits

FreeBSD (70-RELEASE) telnet daemon local privilege escalation - And possible remote root code excution There is a rather big bug in the current FreeBSD telnetd daemon The environment is not properly sanitized when execution /bin/login, what leads to a (possible) remote root hole The telnet protocol allows to pass environment variables inside ...