CVE-2011-4862
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal...
- Published
- Dec 25, 2011
- Updated
- Aug 7, 2024
- Assigning CNA
- freebsd
- Evidence observed
- Dec 26, 2011
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:CHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
Sources
6Final Project for Security and Privacy CS 600.443
- cve-2011-4862Patch
Educational patch implementation for FreeBSD telnetd buffer overflow (CVE-2011-4862) with step-by-step fix explanation and manual patching instructions.
- GO-CVE-2011-4862Exploit
Go-based exploit for CVE-2011-4862 targeting a remote buffer overflow vulnerability, with cross-compilation support for ARM Linux systems.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.