Get a Pentest and security assessment of your IT network.

Advisories

FreeBSD-SA-09:05 – telnetd Code Execution

FreeBSD Security Advisory – In order to prevent environment variable based attacks, telnetd scrubs its environment; however, recent changes in FreeBSD’s environment-handling code rendered telnetd’s scrubbing inoperative, thereby allowing potentially harmful environment variables to be set. An attacker who can place a specially-constructed file onto a target system (either by legitimately logging into the system or by exploiting some other service on the system) can execute arbitrary code with the privileges of the user running the telnet daemon (usually root).

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75012/FreeBSD-SA-09-05.telnetd.txt

Source: https://packetstormsecurity.com/files/75012/FreeBSD-SA-09-05-telnetd-Code-Execution.html

Related posts
Advisories

Secunia Security Advisory 15017

Advisories

Secunia Security Advisory 18394

Advisories

Secunia Security Advisory 21136

Advisories

Secunia Security Advisory 24114