[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-0641Date: (C)2009-02-20   (M)2023-12-22


sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067954.html
BID-33777
EXPLOIT-DB-8055
FreeBSD-SA-09:05
freebsd-telnet-ldpreload-code-execution(48780)

CPE    3
cpe:/o:freebsd:freebsd:7.1:rc1
cpe:/o:freebsd:freebsd:7.0
cpe:/o:freebsd:freebsd:7.1
CWE    1
CWE-264

© SecPod Technologies