HomeGnuCVE-2011-4862

CVE-2011-4862

UNKNOWN
10.0CVSS
Published: 2011-12-25
Updated: 2025-04-11
AI Analysis

Description

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.

CVSS Metrics

Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Access Vector
network
Access Cmplx
low
Auth
none
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
CWE-120

Metadata

Primary Vendor
GNU
Published
12/25/2011
Last Modified
4/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

gnu : inetutilsheimdal_project : heimdalmit : krb5-applfreebsd : freebsdfedoraproject : fedorafedoraproject : fedoradebian : debian_linuxdebian : debian_linuxdebian : debian_linuxopensuse : opensuseopensuse : opensusesuse : linux_enterprise_desktopsuse : linux_enterprise_desktopsuse : linux_enterprise_serversuse : linux_enterprise_serversuse : linux_enterprise_serversuse : linux_enterprise_serversuse : linux_enterprise_serversuse : linux_enterprise_serversuse : linux_enterprise_software_development_kitsuse : linux_enterprise_software_development_kit

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2011-4862 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com