PT-2011-5210 · Mit+3 · Krb5-Server+14

Published

1970-01-01

·

Updated

2025-08-10

·

CVE-2011-4862

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions krb5-appl-clients versions 1.0.1 krb5-devel versions 1.2.7 through 1.6.1 krb5 versions 1.6.1 krb5-devel-64bit (affected versions not specified) krb5-workstation versions 1.2.7 through 1.6.1 krb5-libs versions 1.2.7 through 1.6.1 krb5-appl (affected versions not specified) krb5-appl-servers versions 1.0.1 krb5-64bit (affected versions not specified) krb5-server versions 1.2.7 through 1.6.1 krb5-server-ldap versions 1.6.1
Description The issue may lead to a disruption of confidentiality, integrity, and availability of protected information. It can be exploited remotely. A buffer overflow in libtelnet/encrypt.c in telnetd allows remote attackers to execute arbitrary code via a long encryption key.
Recommendations For krb5-appl-clients version 1.0.1, update to a version that is not affected by this issue. For krb5-devel versions 1.2.7 through 1.6.1, update to a version that is not affected by this issue. For krb5 versions 1.6.1, update to a version that is not affected by this issue. For krb5-devel-64bit, update to a version that is not affected by this issue. For krb5-workstation versions 1.2.7 through 1.6.1, update to a version that is not affected by this issue. For krb5-libs versions 1.2.7 through 1.6.1, update to a version that is not affected by this issue. For krb5-appl, update to a version that is not affected by this issue. For krb5-appl-servers version 1.0.1, update to a version that is not affected by this issue. For krb5-64bit, update to a version that is not affected by this issue. For krb5-server versions 1.2.7 through 1.6.1, update to a version that is not affected by this issue. For krb5-server-ldap version 1.6.1, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03107
BDU:2015-04448
BDU:2015-04449
BDU:2015-05410
BDU:2015-05411
BDU:2015-07292
BDU:2015-07294
BDU:2015-07295
BDU:2015-07296
BDU:2015-07297
BDU:2015-07302
BDU:2015-07304
BDU:2015-07307
BDU:2015-07309
BDU:2015-07314
BDU:2015-07316
BDU:2015-07319
BDU:2015-07322
BDU:2015-07324
CESA-2011_1852
CVE-2011-4862
DSA-2372-1
DSA-2373-1
DSA-2375-1
ELSA-2011-1852
OPENSUSE-SU-2012_0019-1
OPENSUSE-SU-2012_0051-1
OPENSUSE-SU-2024:13497-1
RHSA-2011:1851
RHSA-2011:1852
RHSA-2011:1853
RHSA-2011:1854
RHSA-2011_1851
RHSA-2011_1852
RHSA-2011_1854
TELNETBUFFEROVERFLOW

Affected Products

Centos
Red Hat
Suse
Krb5
Krb5-64Bit
Krb5-Appl
Krb5-Appl-Clients
Krb5-Appl-Servers
Krb5-Devel
Krb5-Devel-64Bit
Krb5-Libs
Krb5-Server
Krb5-Server-Ldap
Krb5-Workstation
Telnet