CVE-2011-4862

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
freebsdCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
gnuinetutils
𝑥
< 1.9
heimdal_projectheimdal
𝑥
≤ 1.5.1
mitkrb5-appl
𝑥
≤ 1.0.2
freebsdfreebsd
7.3 ≤
𝑥
≤ 9.0
debiandebian_linux
5.0
debiandebian_linux
6.0
debiandebian_linux
7.0
opensuseopensuse
11.3
opensuseopensuse
11.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
heimdal
bullseye (security)
7.7.0+dfsg-2+deb11u3
fixed
bullseye
7.7.0+dfsg-2+deb11u3
fixed
bookworm
7.8.git20221117.28daf24+dfsg-2
fixed
sid
7.8.git20221117.28daf24+dfsg-8
fixed
trixie
7.8.git20221117.28daf24+dfsg-8
fixed
inetutils
bullseye
2:2.0-1+deb11u2
fixed
bookworm
2:2.4-2+deb12u1
fixed
sid
2:2.5-5
fixed
trixie
2:2.5-5
fixed
krb5
bullseye (security)
1.18.3-6+deb11u5
fixed
bullseye
1.18.3-6+deb11u5
fixed
bookworm
1.20.1-2+deb12u2
fixed
bookworm (security)
1.20.1-2+deb12u2
fixed
sid
1.21.3-3
fixed
trixie
1.21.3-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
heimdal
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
ignored
raring
ignored
quantal
ignored
precise
not-affected
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
ignored
inetutils
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
ignored
raring
ignored
quantal
ignored
precise
not-affected
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
ignored
krb5
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
ignored
krb5-appl
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
dne
References