MEDIUM
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command
Published Jun 14, 2005
5.0
MEDIUMCVSS 2.0
EPSS 33.03%
Description
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
Affected products
No data.
OR
- enterprise
- r2
- standard
- web
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- http://idefense.com/application/poi/display?id=260&type=vulnerabilities third-party-advisoryx_refsource_IDEFENSEPatchVendor Advisory
- http://secunia.com/advisories/15690/ third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://securitytracker.com/id?1014203 vdb-entryx_refsource_SECTRACK
- http://www.kb.cert.org/vuls/id/800829 third-party-advisoryx_refsource_CERT-VNPatchThird Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/13940 vdb-entryx_refsource_BID
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-033 vendor-advisoryx_refsource_MS
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1132 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A605 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A784 vdb-entrysignaturex_refsource_OVAL
| Link | Providers | Tags |
|---|---|---|
| http://idefense.com/application/poi/display?id=260&type=vulnerabilities | third-party-advisoryx_refsource_IDEFENSEPatchVendor Advisory | |
| http://secunia.com/advisories/15690/ | third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory | |
| http://securitytracker.com/id?1014203 | vdb-entryx_refsource_SECTRACK | |
| http://www.kb.cert.org/vuls/id/800829 | third-party-advisoryx_refsource_CERT-VNPatchThird Party AdvisoryUS Government Resource | |
| http://www.securityfocus.com/bid/13940 | vdb-entryx_refsource_BID | |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-033 | vendor-advisoryx_refsource_MS | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1132 | vdb-entrysignaturex_refsource_OVAL | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A605 | vdb-entrysignaturex_refsource_OVAL | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A784 | vdb-entrysignaturex_refsource_OVAL |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Jun 14, 2005
Updated Aug 7, 2024
Reserved Apr 22, 2005
Link CVE-2005-1205
CISA Vulnrichment
Updated n/a