Sploitus

CVE-2011-4862

19 known exploits for CVE-2011-4862

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.

Gnu Inetutils
< 1.9
Heimdal Project Heimdal
≤ 1.5.1
Mit krb5-appl
≤ 1.0.2
Freebsd
≤ 9.0
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
95.1% (100th percentile)
Weakness
CWE-120
NVD status
Modified
Published
2011-12-25
CVE-2011-4862 at NVD
Authoritative description, scoring and affected products

19 known exploits for CVE-2011-4862

Proof-of-concept code and exploit modules indexed by Sploitus

Telnet Service Encryption Key ID Overflow Detection
2024-08-31 H D Moore, Jaime Penalba, metasploit.comPACKETSTORMRuby
Cisco Ironport WSA telnetd Remote Code Execution Vulnerability
2014-10-24 Glafkos CharalambousZDT
Telnetd Encryption Key ID Code Execution
2012-02-11 SAINT CorporationSAINT
Telnetd Encryption Key ID Code Execution
2012-02-11 SAINT CorporationSAINT
Telnetd Encryption Key ID Code Execution
2012-02-11 SAINT CorporationSAINT
Telnetd Encryption Key ID Code Execution
2012-02-11 SAINT CorporationSAINT
FreeBSD telnetd Remote Root
2012-01-16 knullPACKETSTORMPython
Linux BSD-derived Telnet Service Encryption Key ID Buffer Overflow
2012-01-14 metasploitZDTRuby
FreeBSD Telnet Service Encryption Key ID Buffer Overflow
2012-01-14 Byoungyoung LeeZDTRuby
Linux BSD-derived Telnet Service Encryption Key ID - Remote Buffer Overflow (Metasploit)
2012-01-14 MetasploitEXPLOITDBRuby
FreeBSD - Telnet Service Encryption Key ID Buffer Overflow (Metasploit)
2012-01-14 MetasploitEXPLOITDBRuby
FreeBSD based telnetd encrypt_key_id brute force
2012-01-11 metasploit.comPACKETSTORMRuby
FreeBSD Telnet Service Encryption Key ID Buffer Overflow
2011-12-28 Jaime Penalba Estebanez <jpenalbae@gmail.com>, Brandon Perry <bperry.volatile@gmail.com>, Dan Rosenberg, hdm <x@hdm.io>METASPLOITRuby
Linux BSD-derived Telnet Service Encryption Key ID Buffer Overflow
2011-12-28 Jaime Penalba Estebanez <jpenalbae@gmail.com>, Brandon Perry <bperry.volatile@gmail.com>, Dan Rosenberg, hdm <x@hdm.io>METASPLOITRuby
Linux BSD-derived Telnet Service Encyption Key ID Buffer Overflow
2011-12-28 metasploit.comPACKETSTORMRuby
FreeBSD Telnet Service Encyption Key ID Buffer Overflow
2011-12-28 metasploit.comPACKETSTORMRuby
Telnet Service Encryption Key ID Overflow Detection
2011-12-27 Jaime Penalba Estebanez <jpenalbae@gmail.com>, hdm <x@hdm.io>METASPLOITRuby
TelnetD encrypt_keyid - Function Pointer Overwrite
2011-12-26 NighterMan & BatchDrakeEXPLOITDBC
FreeBSD 'telnetd'守护进程远程缓冲区溢出漏洞
2011-12-26 RootSEEBUG