CVE-2011-4862
25.12.2011, 01:55
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
Vendor | Product | Version |
---|---|---|
gnu | inetutils | 𝑥 < 1.9 |
heimdal_project | heimdal | 𝑥 ≤ 1.5.1 |
mit | krb5-appl | 𝑥 ≤ 1.0.2 |
freebsd | freebsd | 7.3 ≤ 𝑥 ≤ 9.0 |
debian | debian_linux | 5.0 |
debian | debian_linux | 6.0 |
debian | debian_linux | 7.0 |
opensuse | opensuse | 11.3 |
opensuse | opensuse | 11.4 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
heimdal |
| ||||||||||||
inetutils |
| ||||||||||||
krb5 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
heimdal |
| ||||||||||||||||||||||||||||||||
inetutils |
| ||||||||||||||||||||||||||||||||
krb5 |
| ||||||||||||||||||||||||||||||||
krb5-appl |
|
References