CVE-2011-4862 describes a critical buffer overflow vulnerability in the telnetd service's libtelnet/encrypt.c, affecting FreeBSD, MIT Kerberos, Heimdal, GNU inetutils, and potentially other products. This flaw allows remote unauthenticated attackers to execute arbitrary code by sending a long encryption key. With a CVSS score of 10.0 and an EPSS score indicating high exploitability, the vulnerability carries maximum severity, enabling complete compromise of confidentiality, integrity, and availability. Exploitation has been observed in the wild, with multiple Metasploit modules and ExploitDB entries publicly available, demonstrating active and widespread exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9CPE matchmatch criteria | cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:* | ||
<= 1.5.1CPE matchmatch criteria | cpe:2.3:a:heimdal_project:heimdal:*:*:*:*:*:*:*:* | ||
<= 1.0.2CPE matchmatch criteria | cpe:2.3:a:mit:krb5-appl:*:*:*:*:*:*:*:* | ||
>= 7.3, <= 9.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* | ||
15CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.