CVE-2009-0641: Critical severity FreeBSD FreeBSD vulnerability
systerm.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LDPRELOAD value that references a malicious library.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0641?
CVE-2009-0641 is considered to have a moderate severity due to its potential to allow remote code execution.
How do I fix CVE-2009-0641?
To fix CVE-2009-0641, it is recommended to upgrade to a patched version of FreeBSD that addresses this vulnerability.
What software is affected by CVE-2009-0641?
CVE-2009-0641 affects FreeBSD 7.0-RELEASE and other versions within the 7.x series.
What type of attacks can CVE-2009-0641 enable?
CVE-2009-0641 can enable remote attackers to execute arbitrary code on affected systems.
Is CVE-2009-0641 specific to a certain version of FreeBSD?
Yes, CVE-2009-0641 specifically affects several versions of FreeBSD 7.x, including 7.0 and 7.1.