CVE-2005-0488

Description

From CVE.org

Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.

Statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Acknowledgements

Red Hat would like to thank Gaël Delalleau and the MIT Kerberos project for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.