Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-4862

92
FAUCET Score

CVE-2011-4862 describes a critical buffer overflow vulnerability in the telnetd service's libtelnet/encrypt.c, affecting FreeBSD, MIT Kerberos, Heimdal, GNU inetutils, and potentially other products. This flaw allows remote unauthenticated attackers to execute arbitrary code by sending a long encryption key. With a CVSS score of 10.0 and an EPSS score indicating high exploitability, the vulnerability carries maximum severity, enabling complete compromise of confidentiality, integrity, and availability. Exploitation has been observed in the wild, with multiple Metasploit modules and ExploitDB entries publicly available, demonstrating active and widespread exploitability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.9CPE matchmatch criteria
cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:*
<= 1.5.1CPE matchmatch criteria
cpe:2.3:a:heimdal_project:heimdal:*:*:*:*:*:*:*:*
<= 1.0.2CPE matchmatch criteria
cpe:2.3:a:mit:krb5-appl:*:*:*:*:*:*:*:*
>= 7.3, <= 9.0CPE matchmatch criteria
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
15CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
95.10%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: FreeBSD Telnet Service Encryption Key ID Buffer Overflow · Dec 23, 2011
ExploitDB: EDB-18369 · Jan 14, 2012
This CVE's current EPSS score of 0.9510 is in the 100th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3 Extended Lifecycle SupportFixed in: krb5-0:1.2.7-73
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: krb5-0:1.3.4-65.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: krb5-0:1.6.1-63.el5_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.3 Long LifeFixed in: krb5-0:1.6.1-31.el5_3.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.6 EUS - Server OnlyFixed in: krb5-0:1.6.1-55.el5_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: krb5-appl-0:1.0.1-7.el6_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.0 EUS - Server OnlyFixed in: krb5-appl-0:1.0.1-1.el6_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.1 EUS - Server OnlyFixed in: krb5-appl-0:1.0.1-2.el6_1.3
View patch

Vendor Advisories (1)

redhatCVE-2011-4862Critical

krb5: telnet client and server encrypt_keyid heap-based buffer overflow

Dec 25, 2011

References

archives.neohapsis.com / archives/bugtraq/2011-12/0172.html
Broken Link
git.savannah.gnu.org / cgit/inetutils.git/commit
PatchThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2012-January/071627.html
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2012-January/071640.html
Third Party Advisory
lists.freebsd.org / pipermail/freebsd-security/2011-December/006117.html
Vendor Advisory
lists.freebsd.org / pipermail/freebsd-security/2011-December/006118.html
Vendor Advisory
lists.freebsd.org / pipermail/freebsd-security/2011-December/006119.html
Vendor Advisory
lists.freebsd.org / pipermail/freebsd-security/2011-December/006120.html
Vendor Advisory
lists.opensuse.org / opensuse-security-announce/2012-01/msg00002.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2012-01/msg00004.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2012-01/msg00005.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2012-01/msg00007.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2012-01/msg00010.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2012-01/msg00011.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2012-01/msg00014.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2012-01/msg00015.html
Mailing ListThird Party Advisory
osvdb.org / 78020
Broken Link
secunia.com / advisories/46239
Third Party Advisory
secunia.com / advisories/47341
Third Party Advisory
secunia.com / advisories/47348
Third Party Advisory
secunia.com / advisories/47357
Third Party Advisory
secunia.com / advisories/47359
Third Party Advisory
secunia.com / advisories/47373
Third Party Advisory
secunia.com / advisories/47374
Third Party Advisory
secunia.com / advisories/47397
Third Party Advisory
secunia.com / advisories/47399
Third Party Advisory
secunia.com / advisories/47441
Third Party Advisory
security.freebsd.org / advisories/FreeBSD-SA-11:08.telnetd.asc
MitigationVendor Advisory
security.freebsd.org / patches/SA-11:08/telnetd.patch
PatchVendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/71970
Third Party AdvisoryVDB Entry
web.mit.edu / kerberos/www/advisories/MITKRB5-SA-2011-008.txt
PatchVendor Advisory
debian.org / security/2011/dsa-2372
Third Party Advisory
debian.org / security/2011/dsa-2373
Third Party Advisory
debian.org / security/2011/dsa-2375
Third Party Advisory
exploit-db.com / exploits/18280
ExploitThird Party AdvisoryVDB Entry
mandriva.com / security/advisories
Third Party Advisory
redhat.com / support/errata/RHSA-2011-1851.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-1852.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-1853.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-1854.html
Third Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry