CVE-2011-4862 heimdal


2017-12-29 23:00
CVE-2011-4862 krb5
CVE-2011-4862 inetutils
CVE-2011-4862 krb5-appl
2017-12-29 21:03
2017-06-18 07:03
2017-06-16 18:58
2017-04-01 19:11
2017-01-05 20:15


Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
buster heimdal 1.5.dfsg.1-1
jessie heimdal 1.5.dfsg.1-1
sid heimdal 1.5.dfsg.1-1
stretch heimdal 1.5.dfsg.1-1
wheezy heimdal 1.5.dfsg.1-1