Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
- http://www.novell.com/linux/security/advisories/2005_16_sr.html
- https://github.com/Farrhouq/Inpt-report