FreeBSD-SA-09:05 - telnetd Code Execution...

- AV AC AU C I A
发布: 2009-02-17
修订: 2025-04-13

FreeBSD Security Advisory - In order to prevent environment variable based attacks, telnetd scrubs its environment; however, recent changes in FreeBSD's environment-handling code rendered telnetd's scrubbing inoperative, thereby allowing potentially harmful environment variables to be set. An attacker who can place a specially-constructed file onto a target system (either by legitimately logging into the system or by exploiting some other service on the system) can execute arbitrary code with the privileges of the user running the telnet daemon (usually root).

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息