CVE-2009-0641

UnknownEPSS 9.35%

Last modified

CVE-2009-0641 is a vulnerability of currently unknown severity. sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.. EPSS estimates a 9.35% chance of exploitation in the next 30 days.

Description

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.

Metrics

EPSS Probability
9.35%

94.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
FreebsdFreebsd7.0
FreebsdFreebsd7.0-release
FreebsdFreebsd7.0_beta4
FreebsdFreebsd7.0_releng
FreebsdFreebsd7.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-0641?
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.
How severe is CVE-2009-0641?
Severity scoring for CVE-2009-0641 is pending analysis. The EPSS model estimates a 9.35% probability of exploitation in the next 30 days.
How do I fix CVE-2009-0641?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-0641?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST