CVE-2000-0892: Low severity u win u win vulnerability
Published Jul 21, 2001
·Updated
Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.
Affected Software
2 affected components
U Win U Win
Caldera OpenLinux
Remediation
Patch Available
Event History
Jul 21, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0892?
The severity of CVE-2000-0892 is considered moderate due to the potential exposure of sensitive environment variables.
2
How do I fix CVE-2000-0892?
To fix CVE-2000-0892, ensure that your telnet client does not allow remote servers to request environment variables.
3
Which software is affected by CVE-2000-0892?
CVE-2000-0892 affects certain versions of U Win and SCO OpenLinux Server.
4
What information could be exposed in CVE-2000-0892?
CVE-2000-0892 could expose environment variables which may contain sensitive information.
5
Can CVE-2000-0892 be exploited remotely?
Yes, CVE-2000-0892 can be exploited remotely by malicious telnet servers requesting environment variables from clients.