Vulnerability record · CVE-2011-4862 · published 25 December 2011
CVE-2011-4862: telnetd encryption key buffer overflow allows remote code execution
Gnu · Inetutils
A buffer overflow in libtelnet/encrypt.c in telnetd affects FreeBSD 7.3 through 9.0, MIT krb5-appl 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products. A long encryption key overflows the buffer, and the flaw was exploited in the wild in December 2011. Because telnetd is a network-facing service, this is a serious pre-authentication risk on any host still running it.
Description
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, full confidentiality, integrity and availability impact, plus confirmed in-the-wild exploitation.
What it is
A buffer overflow in libtelnet/encrypt.c in telnetd affects FreeBSD 7.3 through 9.0, MIT krb5-appl 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products. A long encryption key overflows the buffer, and the flaw was exploited in the wild in December 2011. Because telnetd is a network-facing service, this is a serious pre-authentication risk on any host still running it.
Impact
A remote attacker can execute arbitrary code with the privileges of the telnetd process, typically root, giving full control of the host.
Attack surface
Reachable over the network via the telnet service (AV:N, AC:L, Au:N); no authentication or user interaction is required per the CVSS vector and description.
Exploitation
NVD states it was exploited in the wild in December 2011, and EPSS is 0.94983 (99.857th percentile), indicating very high predicted exploitation activity; it is not listed in CISA KEV.
What to do
- Patch telnetd and the affected Kerberos application packages (FreeBSD, krb5-appl, Heimdal, inetutils) using the vendor advisories and the GNU inetutils patch reference.
- Disable or remove the telnet service where it is not strictly required.
- Restrict network access to telnetd with firewall rules or network segmentation.
- Replace telnet with SSH for remote administration.
- Monitor vendor advisories for updated packages covering the listed distributions.
Detection
- Inspect telnetd process logs and network traffic for unusually long or malformed encryption key negotiation.
- Alert on unexpected telnet connections to hosts that should not expose the service.
- Monitor for new processes or outbound connections spawned by telnetd.
- Check host inventory for running telnetd instances and unpatched FreeBSD, krb5-appl, Heimdal, or inetutils versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-4862 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4862), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.