CVE-2011-4862: Debian Linux

High severity, CVSS 10.0. EPSS: 95% chance of exploitation in the next 30 days.

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.

Affected products

  • Debian Debian Linux: version 5.0 only; version 6.0 only; version 7.0 only
  • Fedoraproject Fedora: version 15 only; version 16 only
  • Freebsd Freebsd: from 7.3, up to and including 9.0
  • GNU InetUtils: before 1.9 (fixed in 1.9)
  • Heimdal Project Heimdal: up to and including 1.5.1
  • Mit KRB5-Appl: up to and including 1.0.2
  • Opensuse Opensuse: version 11.3 only; version 11.4 only
  • Suse Linux Enterprise Desktop: version 10 only; version 11 only
  • Suse Linux Enterprise Server: version 9 only; version 10 only; version 11 only
  • Suse Linux Enterprise Software Development Kit: version 10 only; version 11 only

Published 2011-12-25. Last modified 2026-06-16.