CVE-2011-4862
25.12.2011, 01:55
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
| Vendor | Product | Version |
|---|---|---|
| gnu | inetutils | 𝑥 < 1.9 |
| heimdal_project | heimdal | 𝑥 ≤ 1.5.1 |
| mit | krb5-appl | 𝑥 ≤ 1.0.2 |
| freebsd | freebsd | 7.3 ≤ 𝑥 ≤ 9.0 |
| debian | debian_linux | 5.0 |
| debian | debian_linux | 6.0 |
| debian | debian_linux | 7.0 |
| opensuse | opensuse | 11.3 |
| opensuse | opensuse | 11.4 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| heimdal |
| ||||||||||||
| inetutils |
| ||||||||||||
| krb5 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| heimdal |
| ||||||||||||||||||||||||||||||||
| inetutils |
| ||||||||||||||||||||||||||||||||
| krb5 |
| ||||||||||||||||||||||||||||||||
| krb5-appl |
|
References