Unrated severityNVD Advisory· Published Feb 20, 2009· Updated Jun 16, 2026
CVE-2009-0641
CVE-2009-0641
Description
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:o:freebsd:freebsd:7.0-release:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:o:freebsd:freebsd:7.0-release:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:7.0:beta_4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:7.0:current:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:7.0_beta4:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:7.0_releng:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:7.1:rc1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.