telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Inetutils | Gnu | * | 2.7 (including) |
| Inetutils | Ubuntu | devel | * |
| Inetutils | Ubuntu | esm-apps-legacy/xenial | * |
| Inetutils | Ubuntu | esm-apps/bionic | * |
| Inetutils | Ubuntu | esm-apps/focal | * |
| Inetutils | Ubuntu | esm-apps/jammy | * |
| Inetutils | Ubuntu | esm-apps/xenial | * |
| Inetutils | Ubuntu | esm-infra-legacy/trusty | * |
| Inetutils | Ubuntu | jammy | * |
| Inetutils | Ubuntu | noble | * |
| Inetutils | Ubuntu | questing | * |
| Inetutils | Ubuntu | resolute | * |