Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
{ "urgency": "unimportant" }
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-0488.json"