PT-2011-5210 · Mit+3 · Krb5-Server+14
Published
1970-01-01
·
Updated
2025-08-10
·
CVE-2011-4862
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
krb5-appl-clients versions 1.0.1
krb5-devel versions 1.2.7 through 1.6.1
krb5 versions 1.6.1
krb5-devel-64bit (affected versions not specified)
krb5-workstation versions 1.2.7 through 1.6.1
krb5-libs versions 1.2.7 through 1.6.1
krb5-appl (affected versions not specified)
krb5-appl-servers versions 1.0.1
krb5-64bit (affected versions not specified)
krb5-server versions 1.2.7 through 1.6.1
krb5-server-ldap versions 1.6.1
Description
The issue may lead to a disruption of confidentiality, integrity, and availability of protected information. It can be exploited remotely. A buffer overflow in libtelnet/encrypt.c in telnetd allows remote attackers to execute arbitrary code via a long encryption key.
Recommendations
For krb5-appl-clients version 1.0.1, update to a version that is not affected by this issue.
For krb5-devel versions 1.2.7 through 1.6.1, update to a version that is not affected by this issue.
For krb5 versions 1.6.1, update to a version that is not affected by this issue.
For krb5-devel-64bit, update to a version that is not affected by this issue.
For krb5-workstation versions 1.2.7 through 1.6.1, update to a version that is not affected by this issue.
For krb5-libs versions 1.2.7 through 1.6.1, update to a version that is not affected by this issue.
For krb5-appl, update to a version that is not affected by this issue.
For krb5-appl-servers version 1.0.1, update to a version that is not affected by this issue.
For krb5-64bit, update to a version that is not affected by this issue.
For krb5-server versions 1.2.7 through 1.6.1, update to a version that is not affected by this issue.
For krb5-server-ldap version 1.6.1, update to a version that is not affected by this issue.
As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Krb5
Krb5-64Bit
Krb5-Appl
Krb5-Appl-Clients
Krb5-Appl-Servers
Krb5-Devel
Krb5-Devel-64Bit
Krb5-Libs
Krb5-Server
Krb5-Server-Ldap
Krb5-Workstation
Telnet