Vulnerabilities > CVE-2009-0641 - Configuration vulnerability in Freebsd
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 8 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | FreeBSD 7.0-RELEASE Telnet Daemon Local Privilege Escalation Exploit. CVE-2009-0641. Local exploit for freebsd platform |
file | exploits/freebsd/local/8055.txt |
id | EDB-ID:8055 |
last seen | 2016-02-01 |
modified | 2009-02-16 |
platform | freebsd |
port | |
published | 2009-02-16 |
reporter | kingcope |
source | https://www.exploit-db.com/download/8055/ |
title | FreeBSD 7.0-RELEASE Telnet Daemon - Local Privilege Escalation Exploit |
type | local |
Nessus
NASL family | Gain a shell remotely |
NASL id | FREEBSD_TELNETD_CODE_EXEC.NASL |
description | A flaw in the environment-handling code used by the telnet server running on the remote host fails to scrub the environment of variables such as |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 35700 |
published | 2009-02-17 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/35700 |
title | FreeBSD telnetd sys_term.c Environment Variable Handling Privilege Escalation (FreeBSD-SA-09:05) |
code |
|
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067954.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067954.html
- http://security.freebsd.org/advisories/FreeBSD-SA-09:05.telnetd.asc
- http://security.freebsd.org/advisories/FreeBSD-SA-09:05.telnetd.asc
- http://www.securityfocus.com/bid/33777
- http://www.securityfocus.com/bid/33777
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48780
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48780
- https://www.exploit-db.com/exploits/8055
- https://www.exploit-db.com/exploits/8055