CVE-2011-4862: Debian Linux
High severity, CVSS 10.0. EPSS: 95% chance of exploitation in the next 30 days.
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
Affected products
- Debian Debian Linux: version 5.0 only; version 6.0 only; version 7.0 only
- Fedoraproject Fedora: version 15 only; version 16 only
- Freebsd Freebsd: from 7.3, up to and including 9.0
- GNU InetUtils: before 1.9 (fixed in 1.9)
- Heimdal Project Heimdal: up to and including 1.5.1
- Mit KRB5-Appl: up to and including 1.0.2
- Opensuse Opensuse: version 11.3 only; version 11.4 only
- Suse Linux Enterprise Desktop: version 10 only; version 11 only
- Suse Linux Enterprise Server: version 9 only; version 10 only; version 11 only
- Suse Linux Enterprise Software Development Kit: version 10 only; version 11 only
Published 2011-12-25. Last modified 2026-06-16.