>> Redhat Security Update Fixes Telnet Client Information Disclosure
Title : Redhat Security Update Fixes Telnet Client Information Disclosure VUPEN ID : VUPEN/ADV-2005-0786 CVE ID : CVE-2005-0488 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-06-16
Technical Description
Redhat has released a security patch to correct a vulnerability identified in Telnet. This flaw occurs when processing the "NEW-ENVIRON" option with a "SEND ENV_USERVAR" command, which could be exploited by remote attackers to read sensitive environment variables.