Multiple Vendor Telnet Client Remote Information Disclosure Vulnerability
BID:13940
Info
Multiple Vendor Telnet Client Remote Information Disclosure Vulnerability
| Bugtraq ID: | 13940 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-1205 CVE-2005-0488 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2005 12:00AM |
| Updated: | Aug 02 2006 08:16PM |
| Credit: | Gael Delalleau is credited for reporting this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 7 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SuSE Linux 7.3 sparc SuSE Linux 7.3 ppc SuSE Linux 7.3 i386 SuSE Linux 7.3 SuSE Linux 7.2 i386 SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.1 SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 i386 SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 i386 SuSE Linux 6.4 alpha SuSE Linux 6.4 SuSE Linux 6.3 ppc SuSE Linux 6.3 alpha SuSE Linux 6.3 SuSE Linux 6.2 SuSE Linux 6.1 alpha SuSE Linux 6.1 SuSE Linux 6.0 SuSE Linux 5.3 SuSE Linux 5.2 SuSE Linux 5.1 SuSE Linux 5.0 SuSE Linux 4.4.1 SuSE Linux 4.4 SuSE Linux 4.3 SuSE Linux 4.2 SuSE Linux 4.0 SuSE Linux 3.0 SuSE Linux 2.0 SuSE Linux 1.0 Sun SunOS 5.9 _x86 Sun SunOS 5.9 Sun SunOS 5.8 _x86 Sun SunOS 5.8 Sun SunOS 5.7 _x86 Sun SunOS 5.7 Sun Solaris 9_x86 Update 2 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.8 Sun Solaris 2.7_sparc Sun Solaris 2.7 Sun Solaris 10 Sun SEAM 1.0.2 Sun SEAM 1.0.1 Sun SEAM 1.0 SGI ProPack 3.0 SP6 SGI ProPack 3.0 SP5 SCO Unixware 7.1.4 SCO Unixware 7.1.3 SCO Open Server 5.0.7 SCO Open Server 5.0.6 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SuSE eMail Server III S.u.S.E. SuSE eMail Server 3.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 7.3 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Office Server S.u.S.E. Linux IMAP Server 1.0 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 MIT Kerberos 5 1.3.6 Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP1 Beta 1 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Services for Unix 3.5 Microsoft Services for Unix 3.0 Microsoft Services for Unix 2.2 Microsoft Services for Unix 2.1 Microsoft Services for Unix 2.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 F5 BIG-IP 4.6.3 F5 BIG-IP 4.6.2 F5 BIG-IP 4.6 F5 BIG-IP 4.5.12 F5 BIG-IP 4.5.11 F5 BIG-IP 4.5.10 F5 BIG-IP 4.5.9 F5 BIG-IP 4.5.6 F5 BIG-IP 4.5 F5 BIG-IP 4.4 F5 BIG-IP 4.3 F5 BIG-IP 4.2 F5 BIG-IP 4.0 F5 3-DNS 4.6.3 F5 3-DNS 4.6.2 F5 3-DNS 4.6 F5 3-DNS 4.5.12 F5 3-DNS 4.5.11 F5 3-DNS 4.5 F5 3-DNS 4.4 F5 3-DNS 4.3 F5 3-DNS 4.2 Cosmicperl Directory Pro 10.0.3 Avaya S8710 R2.0.1 Avaya S8710 R2.0.0 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8500 R2.0.1 Avaya S8500 R2.0.0 Avaya S8300 R2.0.1 Avaya S8300 R2.0.0 Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya MN100 Avaya Intuity LX Avaya Converged Communications Server 2.0 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X Server 10.1.5 Apple Mac OS X Server 10.1.4 Apple Mac OS X Server 10.1.3 Apple Mac OS X Server 10.1.2 Apple Mac OS X Server 10.1.1 Apple Mac OS X Server 10.1 Apple Mac OS X Server 10.0 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 |
| Not Vulnerable: |
F5 BIG-IP 4.7 F5 BIG-IP 4.5.13 F5 3-DNS 4.7 F5 3-DNS 4.5.13 |
Discussion
Multiple Vendor Telnet Client Remote Information Disclosure Vulnerability
Telnet clients provided by multiple vendors are prone to a remote information-disclosure vulnerability.
Attackers can retrieve any information stored in the environment of clients using the affected telnet application. The contents of the environment variables may be sensitive in nature, allowing attackers to gain information that may aid them in further attacks.
Telnet clients provided by multiple vendors are prone to a remote information-disclosure vulnerability.
Attackers can retrieve any information stored in the environment of clients using the affected telnet application. The contents of the environment variables may be sensitive in nature, allowing attackers to gain information that may aid them in further attacks.
Exploit / POC
Multiple Vendor Telnet Client Remote Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor Telnet Client Remote Information Disclosure Vulnerability
Solution:
Please see the referenced advisories for more information.
Microsoft Windows Server 2003 Datacenter Edition SP1
Microsoft Windows Server 2003 Standard Edition SP1
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Enterprise x64 Edition
Microsoft Windows XP Professional
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Microsoft Windows Server 2003 Standard Edition SP1 Beta 1
Sun Solaris 7.0
Microsoft Windows XP Home SP1
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP 64-bit Edition Version 2003 SP1
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows XP 64-bit Edition
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1
Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Sun SEAM 1.0.1
Sun SEAM 1.0.2
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Solution:
Please see the referenced advisories for more information.
Microsoft Windows Server 2003 Datacenter Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=22095E78-A559 -40EA-8B65-9C727F4E752F
Microsoft Windows Server 2003 Standard Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=22095E78-A559 -40EA-8B65-9C727F4E752F
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=22095E78-A559 -40EA-8B65-9C727F4E752F
Microsoft Windows Server 2003 Enterprise x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=DCC6840F-E626 -4266-A63A-CDDEC0EC44D6
Microsoft Windows XP Professional
-
Microsoft Security Update for Windows XP (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=B8BA775E-E9A7 -47E9-81A9-A68A71B9FAAC
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Itanium Edition and Windows XP 64-bit Itanium Edition
http://www.microsoft.com/downloads/details.aspx?familyid=C23A4E16-E228 -4A80-A4CB-9DCEF462B97A
Microsoft Windows Server 2003 Standard Edition SP1 Beta 1
-
Microsoft Security Update for Windows Server 2003 (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=22095E78-A559 -40EA-8B65-9C727F4E752F
Sun Solaris 7.0
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=B8BA775E-E9A7 -47E9-81A9-A68A71B9FAAC
Microsoft Windows XP Professional x64 Edition
-
Microsoft Security Update for Windows XP x64 Edition (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=B281550B-8FAE -4FF3-9BB7-E4BA325779B9
Microsoft Windows XP 64-bit Edition Version 2003 SP1
-
Microsoft Security Update for Windows Server 2003 64-bit Itanium Edition and Windows XP 64-bit Itanium Edition
http://www.microsoft.com/downloads/details.aspx?familyid=C23A4E16-E228 -4A80-A4CB-9DCEF462B97A -
Microsoft unused
Microsoft Windows XP 64-bit Edition Version 2003
-
Microsoft Security Update for Windows Server 2003 64-bit Itanium Edition and Windows XP 64-bit Itanium Edition
http://www.microsoft.com/downloads/details.aspx?familyid=C23A4E16-E228 -4A80-A4CB-9DCEF462B97A -
Microsoft unused
Microsoft Windows XP 64-bit Edition
-
Microsoft Security Update for Windows XP 64-bit Itanium Edition (KB896428)
http://www.microsoft.com/downloads/details.aspx?FamilyId=C6161D9E-1672 -479E-8BAF-754A64DFAB47
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1
-
Microsoft Security Update for Windows Server 2003 64-bit Itanium Edition and Windows XP 64-bit Itanium Edition
http://www.microsoft.com/downloads/details.aspx?familyid=C23A4E16-E228 -4A80-A4CB-9DCEF462B97A
Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1
-
Microsoft Security Update for Windows Server 2003 (KB896428)
http://www.microsoft.com/downloads/details.aspx?familyid=22095E78-A559 -40EA-8B65-9C727F4E752F
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Itanium Edition and Windows XP 64-bit Itanium Edition
http://www.microsoft.com/downloads/details.aspx?familyid=C23A4E16-E228 -4A80-A4CB-9DCEF462B97A
Sun SEAM 1.0.1
-
Sun 110060-19
SPARC
http://sunsolve.sun.com/search/document.do?assetkey=1-21-110060-19-1 -
Sun 110061-18
x86
http://sunsolve.sun.com/search/document.do?assetkey=1-21-110061-18-1
Sun SEAM 1.0.2
-
Sun 116462-04
SPARC
http://sunsolve.sun.com/search/document.do?assetkey=1-21-110061-18-1 -
Sun 119796-02
x86
http://sunsolve.sun.com/search/document.do?assetkey=1-21-119796-02-1
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2006-004Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=11231&cat= 1&platform=osx&method=sa/SecUpdSrvr2006-004Pan.dmg
Apple Mac OS X 10.3.9
References
Multiple Vendor Telnet Client Remote Information Disclosure Vulnerability
References:
References:
- ASA-2005-145 - telnet security update (Avaya)
- Microsoft Security Bulletin MS05-033 (Microsoft)
- RHSA-2005:562-15 - krb5 security update (RedHat)
- RHSA-2005:567-08 - krb5 security update (RedHat)
- Services For Unix Product Page (Microsoft)
- Solution ID: SOL4616 (F5 Software)
- Sun Alert ID: 101665 (formerly 57755) (Sun)
- Sun Alert ID: 101671 (formerly 57761) (Sun)
- iDEFENSE Security Advisory 06.14.05: Multiple Vendor Telnet Client Information D ("iDEFENSE Labs"
)