CVE-2011-4862

EUVD-2011-4779
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
gnuinetutils
𝑥
< 1.9
heimdal_projectheimdal
𝑥
≤ 1.5.1
mitkrb5-appl
𝑥
≤ 1.0.2
freebsdfreebsd
7.3 ≤
𝑥
≤ 9.0
debiandebian_linux
5.0
debiandebian_linux
6.0
debiandebian_linux
7.0
opensuseopensuse
11.3
opensuseopensuse
11.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
heimdal
bookworm
7.8.git20221117.28daf24+dfsg-2
fixed
bullseye
7.7.0+dfsg-2+deb11u3
fixed
bullseye (security)
7.7.0+dfsg-2+deb11u3
fixed
sid
7.8.git20221117.28daf24+dfsg-8
fixed
trixie
7.8.git20221117.28daf24+dfsg-8
fixed
inetutils
bookworm
2:2.4-2+deb12u1
fixed
bullseye
2:2.0-1+deb11u2
fixed
sid
2:2.5-5
fixed
trixie
2:2.5-5
fixed
krb5
bookworm
1.20.1-2+deb12u2
fixed
bookworm (security)
1.20.1-2+deb12u2
fixed
bullseye
1.18.3-6+deb11u5
fixed
bullseye (security)
1.18.3-6+deb11u5
fixed
sid
1.21.3-3
fixed
trixie
1.21.3-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
heimdal
hardy
ignored
lucid
ignored
maverick
ignored
natty
ignored
oneiric
ignored
precise
not-affected
quantal
ignored
raring
ignored
saucy
ignored
trusty
not-affected
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
inetutils
hardy
ignored
lucid
ignored
maverick
ignored
natty
ignored
oneiric
ignored
precise
not-affected
quantal
ignored
raring
ignored
saucy
ignored
trusty
not-affected
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
krb5
hardy
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
not-affected
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
krb5-appl
hardy
dne
lucid
ignored
maverick
ignored
natty
ignored
oneiric
ignored
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
References