CVE-2009-0641
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 9.32% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16, CWE-264
- Affected
- freebsd/freebsd
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067954.htmlExploit
- http://security.freebsd.org/advisories/FreeBSD-SA-09:05.telnetd.ascPatch
- http://www.securityfocus.com/bid/33777Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48780
- https://www.exploit-db.com/exploits/8055
- http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067954.htmlExploit
- http://security.freebsd.org/advisories/FreeBSD-SA-09:05.telnetd.ascPatch
- http://www.securityfocus.com/bid/33777Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48780
- https://www.exploit-db.com/exploits/8055
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.