First published: Tue Jun 14 2005(Updated: )
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =enterprise | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows 2003 Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1205 has a moderate severity level due to its potential to expose sensitive environment variables.
To fix CVE-2005-1205, disable the Telnet client or apply relevant patches and updates provided by Microsoft.
CVE-2005-1205 affects the Telnet client on Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX.
Yes, CVE-2005-1205 can be exploited remotely by attackers sending SEND ENV_USERVAR commands.
CVE-2005-1205 introduces risks related to unauthorized access to sensitive environment variables.