← All CVEs

CVE-2011-4862

high · 10

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.

10
CVSS
95.0%
EPSS (exploit prob.)
100th
EPSS percentile
2011-12-25
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-120

Affected products

VendorProductAffected versions
gnuinetutils< 1.9
heimdal_projectheimdal<= 1.5.1
mitkrb5-appl<= 1.0.2
freebsdfreebsd>= 7.3, <= 9.0
fedoraprojectfedora15
fedoraprojectfedora16
debiandebian_linux5.0
debiandebian_linux6.0
debiandebian_linux7.0
opensuseopensuse11.3
opensuseopensuse11.4
suselinux_enterprise_desktop10
suselinux_enterprise_desktop11
suselinux_enterprise_server9
suselinux_enterprise_server10
suselinux_enterprise_server10
suselinux_enterprise_server10
suselinux_enterprise_server11
suselinux_enterprise_server11
suselinux_enterprise_software_development_kit10
suselinux_enterprise_software_development_kit11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-4862