>> SCO Security Update Fixes Telnet Client Information Disclosure Issue
Title : SCO Security Update Fixes Telnet Client Information Disclosure Issue VUPEN ID : VUPEN/ADV-2005-2483 CVE ID : CVE-2005-0488
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-11-18
Technical Description
SCO has released updated packages to correct a vulnerability identified in Telnet. This flaw occurs when processing the "NEW-ENVIRON" option with a "SEND ENV_USERVAR" command, which could be exploited by remote attackers to read sensitive environment variables. For additional information, see : VUPEN/ADV-2005-0786