Vulnerability Details CVE-2009-0641
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.057
EPSS Ranking 90.1%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2009-0641
-
cpe:2.3:o:freebsd:freebsd:7.0
-
cpe:2.3:o:freebsd:freebsd:7.0-release
-
cpe:2.3:o:freebsd:freebsd:7.0_beta4
-
cpe:2.3:o:freebsd:freebsd:7.0_releng
-
cpe:2.3:o:freebsd:freebsd:7.1