CVE-2009-0641
HIGH 9.3EPSS 9.3%
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.
- CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 9.32% chance of exploitation in the next 30 days, 95th percentile
- Published
- 2009-02-18
- Updated
- 2024-08-07