| Definition Id: oval:org.mitre.oval:def:605 |
Version: 4
Last Modified: 2011-04-26
|
| Title: |
Server 2003 Telnet Environment Disclosure Vulnerability |
| Description: |
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command. |
| Family: |
windows |
Class: |
vulnerability |
| Status: |
ACCEPTED |
Reference(s): |
CVE-2005-1205
|
| Platform(s): |
Microsoft Windows Server 2003 |
Product(s): |
Services for UNIX |
| Definition Synopsis: |
- Windows Server 2003 is installed
- AND a vulnerable version of telnet.exe exists
- for specific Windows configurations a vulnerable version of telnet.exe exists
- OR for specific Windows configurations a vulnerable version of telnet.exe exists
- OR for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of telnet.exe exists
- AND NOT the patch KB896428 is installed
|