First published: Fri Feb 20 2009(Updated: )
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =7.0 | |
FreeBSD Kernel | =7.0-beta_4 | |
FreeBSD Kernel | =7.0-current | |
FreeBSD Kernel | =7.0-release | |
FreeBSD Kernel | =7.0_beta4 | |
FreeBSD Kernel | =7.0_releng | |
FreeBSD Kernel | =7.1 | |
FreeBSD Kernel | =7.1-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0641 is considered to have a moderate severity due to its potential to allow remote code execution.
To fix CVE-2009-0641, it is recommended to upgrade to a patched version of FreeBSD that addresses this vulnerability.
CVE-2009-0641 affects FreeBSD 7.0-RELEASE and other versions within the 7.x series.
CVE-2009-0641 can enable remote attackers to execute arbitrary code on affected systems.
Yes, CVE-2009-0641 specifically affects several versions of FreeBSD 7.x, including 7.0 and 7.1.