CVE-2011-4862: Buffer Overflow
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4862?
CVE-2011-4862 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2011-4862?
To fix CVE-2011-4862, upgrade to the latest versions of the affected software listed in the vulnerability report.
Which software versions are affected by CVE-2011-4862?
CVE-2011-4862 affects FreeBSD 7.3 through 9.0, MIT Kerberos krb5-appl 1.0.2 and earlier, Heimdal 1.5.1 and earlier, and GNU inetutils.
Can CVE-2011-4862 be exploited remotely?
Yes, CVE-2011-4862 can be exploited remotely by attackers through the use of a lengthy encryption key.
Is there a known exploit for CVE-2011-4862?
While specific exploits may not be publicly disclosed, the nature of CVE-2011-4862 indicates that it is vulnerable to remote code execution exploits.