cbcvebase.
CVE-2011-4862
published 2011-12-25

CVE-2011-4862: Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal…

critical10CVSS 3.1
AVNACLAuNCCICAC
ITWEXPLOIT
Exploited in the wild
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoironport_appliances_telnet
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianheimdal< heimdal 1.5.dfsg.1-1 (bookworm)heimdal 1.5.dfsg.1-1 (bookworm)
debianinetutils< heimdal 1.5.dfsg.1-1 (bookworm)heimdal 1.5.dfsg.1-1 (bookworm)
debiankrb5< heimdal 1.5.dfsg.1-1 (bookworm)heimdal 1.5.dfsg.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
freebsdfreebsd7.3 – 9.0
gnuinetutils< 1.91.9
gnuinetutils>= 0 < 2:1.8-62:1.8-6
gnuinetutils>= 0 < 2:1.8-62:1.8-6
gnuinetutils>= 0 < 2:1.8-62:1.8-6
gnuinetutils>= 0 < 2:1.8-62:1.8-6
heimdal_projectheimdal<= 1.5.1
heimdal_projectheimdal>= 0 < 1.5.dfsg.1-11.5.dfsg.1-1
heimdal_projectheimdal>= 0 < 1.5.dfsg.1-11.5.dfsg.1-1
heimdal_projectheimdal>= 0 < 1.5.dfsg.1-11.5.dfsg.1-1
heimdal_projectheimdal>= 0 < 1.5.dfsg.1-11.5.dfsg.1-1
mitkrb5>= 0 < 1.8+dfsg~aa+r23527-11.8+dfsg~aa+r23527-1
mitkrb5>= 0 < 1.8+dfsg~aa+r23527-11.8+dfsg~aa+r23527-1
mitkrb5>= 0 < 1.8+dfsg~aa+r23527-11.8+dfsg~aa+r23527-1
mitkrb5>= 0 < 1.8+dfsg~aa+r23527-11.8+dfsg~aa+r23527-1
mitkrb5-appl<= 1.0.2

CVSS provenance

nvd10.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck10.0CRITICAL