krb5: telnet client and server encrypt_keyid heap-based buffer overflow
Published Dec 25, 2011
10.0
HIGHCVSS 2.0
EPSS 94.98%
Description
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
Affected products
No data.
Configuration 1
Configuration 2
- 15
- 16
Configuration 3
- 5.0
- 6.0
- 7.0
Configuration 4
- 11.3
- 11.4
- 10
- 11
- 9
- 10
- 10
- 10
- 11
- 11
- 10
- 11
No data.
Red Hat Enterprise Linux 3 Extended Lifecycle Support
krb5-0:1.2.7-73
Fixed · RHSA-2011:1853
Red Hat Enterprise Linux 4
krb5-0:1.3.4-65.el4
Fixed · RHSA-2011:1851
Red Hat Enterprise Linux 5
krb5-0:1.6.1-63.el5_7
Fixed · RHSA-2011:1851
Red Hat Enterprise Linux 5.3 Long Life
krb5-0:1.6.1-31.el5_3.5
Fixed · RHSA-2011:1853
Red Hat Enterprise Linux 5.6 EUS - Server Only
krb5-0:1.6.1-55.el5_6.3
Fixed · RHSA-2011:1853
Red Hat Enterprise Linux 6
krb5-appl-0:1.0.1-7.el6_2
Fixed · RHSA-2011:1852
Red Hat Enterprise Linux 6.0 EUS - Server Only
krb5-appl-0:1.0.1-1.el6_0.1
Fixed · RHSA-2011:1854
Red Hat Enterprise Linux 6.1 EUS - Server Only
krb5-appl-0:1.0.1-2.el6_1.3
Fixed · RHSA-2011:1854
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 Extended Lifecycle Support | krb5-0:1.2.7-73 | Fixed | RHSA-2011:1853 |
| Red Hat Enterprise Linux 4 | krb5-0:1.3.4-65.el4 | Fixed | RHSA-2011:1851 |
| Red Hat Enterprise Linux 5 | krb5-0:1.6.1-63.el5_7 | Fixed | RHSA-2011:1851 |
| Red Hat Enterprise Linux 5.3 Long Life | krb5-0:1.6.1-31.el5_3.5 | Fixed | RHSA-2011:1853 |
| Red Hat Enterprise Linux 5.6 EUS - Server Only | krb5-0:1.6.1-55.el5_6.3 | Fixed | RHSA-2011:1853 |
| Red Hat Enterprise Linux 6 | krb5-appl-0:1.0.1-7.el6_2 | Fixed | RHSA-2011:1852 |
| Red Hat Enterprise Linux 6.0 EUS - Server Only | krb5-appl-0:1.0.1-1.el6_0.1 | Fixed | RHSA-2011:1854 |
| Red Hat Enterprise Linux 6.1 EUS - Server Only | krb5-appl-0:1.0.1-2.el6_1.3 | Fixed | RHSA-2011:1854 |
No package ranges for this CVE.
Remediation
Red Hat statement
A buffer overflow flaw was found in the MIT krb5 telnet daemon (telnetd) as shipped with all supported versions of Red Hat Enterprise Linux. A remote attacker who can access the telnet port of a target machine could use this flaw to execute arbitrary code as root. While we are aware of public exploits for this issue that include targets for Red Hat Enterprise Linux 3, we are not aware of any yet which would be successful in gaining arbitrary root code execution in Red Hat Enterprise Linux 4, 5, or 6. However it is plausible that one could be created to do so. Note that the krb5 telnet daemon is not enabled by default in any version of Red Hat Enterprise Linux. In addition, the default firewall rules block remote access to the telnet port. This flaw does not affect the telnet daemon distributed in the telnet-server package. For users who have enabled the krb5 telnet daemon and have it accessible remotely, they should disable it or apply the updates we have released. Since same encryption code is shared between the MIT krb5 telnet daemon and the telnet client, this issue affects the telnet client as well. The updates we have released fixes the issue for both, the telnet daemon and the telnet client.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 94.98% (0.94983) | 99.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 95.10% (0.95104) | 99.85th | v5 (v2026.06.15) |
| Mar 17, 2025 | 92.58% (0.92585) | 99.74th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.75% (0.96745) | 99.72th | v3 (v2023.03.01) |
| Jun 24, 2024 | 96.79% (0.96787) | 99.69th | v3 (v2023.03.01) |
| May 2, 2024 | 96.94% (0.96938) | 99.72th | v3 (v2023.03.01) |
| Mar 8, 2024 | 97.19% (0.97188) | 99.80th | v3 (v2023.03.01) |
| Jan 12, 2024 | 97.25% (0.97252) | 99.81th | v3 (v2023.03.01) |
| Sep 22, 2023 | 97.31% (0.97306) | 99.81th | v3 (v2023.03.01) |
| May 21, 2023 | 97.42% (0.97418) | 99.88th | v3 (v2023.03.01) |
| Mar 19, 2023 | 97.40% (0.97402) | 99.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.38% (0.97381) | 99.80th | v3 (v2023.03.01) |
| Mar 6, 2023 | 86.82% (0.86822) | 99.72th | v2 (v2022.01.01) |
| Feb 13, 2023 | 86.82% (0.86822) | 99.72th | v2 (v2022.01.01) |
| Nov 26, 2022 | 90.67% (0.90669) | 99.86th | v2 (v2022.01.01) |
| Jun 9, 2022 | 88.70% (0.88698) | 99.80th | v2 (v2022.01.01) |
| Mar 9, 2022 | 88.47% (0.88473) | 99.77th | v2 (v2022.01.01) |
| Feb 4, 2022 | 88.82% (0.88824) | 99.78th | v2 (v2022.01.01) |
References (46)
- http://archives.neohapsis.com/archives/bugtraq/2011-12/0172.html mailing-listx_refsource_BUGTRAQBroken Link
- http://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=665f1e73cdd9b38e2d2e11b8db9958a315935592 x_refsource_CONFIRMPatchThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071627.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071640.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.freebsd.org/pipermail/freebsd-security/2011-December/006117.html mailing-listx_refsource_MLISTVendor Advisory
- http://lists.freebsd.org/pipermail/freebsd-security/2011-December/006118.html mailing-listx_refsource_MLISTVendor Advisory
- http://lists.freebsd.org/pipermail/freebsd-security/2011-December/006119.html mailing-listx_refsource_MLISTVendor Advisory
- http://lists.freebsd.org/pipermail/freebsd-security/2011-December/006120.html mailing-listx_refsource_MLISTVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00007.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://osvdb.org/78020 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/46239 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47341 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47348 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47357 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47359 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47373 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47374 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47397 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47399 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/47441 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-11:08.telnetd.asc vendor-advisoryx_refsource_FREEBSDMitigationVendor Advisory
- http://security.freebsd.org/patches/SA-11:08/telnetd.patch x_refsource_CONFIRMPatchVendor Advisory
- http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2011-008.txt x_refsource_CONFIRMPatchVendor Advisory
- http://www.debian.org/security/2011/dsa-2372 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.debian.org/security/2011/dsa-2373 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.debian.org/security/2011/dsa-2375 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.exploit-db.com/exploits/18280/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:195 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1851.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1852.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1853.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1854.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securitytracker.com/id?1026460 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1026463 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2011-4862 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=770325 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71970 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2011-4862
- https://www.cve.org/CVERecord?id=CVE-2011-4862
Change history (0)
No recorded changes yet.