CVE-2005-0488: Medium severity Microsoft Telnet Client vulnerability
Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENVUSERVAR command.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0488?
CVE-2005-0488 is classified as a medium severity vulnerability due to its potential to expose sensitive environment variables.
How do I fix CVE-2005-0488?
To fix CVE-2005-0488, disable the NEW-ENVIRON option on your Telnet clients or upgrade to an unaffected version.
Which systems are affected by CVE-2005-0488?
CVE-2005-0488 affects certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux.
Can CVE-2005-0488 be exploited remotely?
Yes, CVE-2005-0488 can be exploited remotely by malicious Telnet servers that can send crafted commands.
What type of data can be exposed through CVE-2005-0488?
CVE-2005-0488 can allow remote attackers to read sensitive environment variables from the affected Telnet clients.