Lucene search

K
cveMitreCVE-2009-0641
HistoryFeb 20, 2009 - 6:47 a.m.

CVE-2009-0641

2009-02-2006:47:48
CWE-264
CWE-16
mitre
web.nvd.nist.gov
31
telnetd
freebsd
cve-2009-0641
remote code execution
environment variables
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.083

Percentile

94.5%

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.

Affected configurations

Nvd
Node
freebsdfreebsdMatch7.0
OR
freebsdfreebsdMatch7.0beta_4
OR
freebsdfreebsdMatch7.0current
OR
freebsdfreebsdMatch7.0-release
OR
freebsdfreebsdMatch7.0_beta4
OR
freebsdfreebsdMatch7.0_releng
OR
freebsdfreebsdMatch7.1
OR
freebsdfreebsdMatch7.1rc1
VendorProductVersionCPE
freebsdfreebsd7.0cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*
freebsdfreebsd7.0cpe:2.3:o:freebsd:freebsd:7.0:beta_4:*:*:*:*:*:*
freebsdfreebsd7.0cpe:2.3:o:freebsd:freebsd:7.0:current:*:*:*:*:*:*
freebsdfreebsd7.0-releasecpe:2.3:o:freebsd:freebsd:7.0-release:*:*:*:*:*:*:*
freebsdfreebsd7.0_beta4cpe:2.3:o:freebsd:freebsd:7.0_beta4:*:*:*:*:*:*:*
freebsdfreebsd7.0_relengcpe:2.3:o:freebsd:freebsd:7.0_releng:*:*:*:*:*:*:*
freebsdfreebsd7.1cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:*
freebsdfreebsd7.1cpe:2.3:o:freebsd:freebsd:7.1:rc1:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.083

Percentile

94.5%