vendor:
FreeBSD
by:
Jaime Penalba Estebanez, Brandon Perry, Dan Rosenberg, hdm
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FreeBSD
Affected Version From: FreeBSD 5.3
Affected Version To: FreeBSD 8.2
Patch Exists: YES
Related CWE: CVE-2011-4862
CPE: o:freebsd:freebsd
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-1851/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-1854/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-4ddc78dc-300a-11e1-a2aa-0016ce01e285/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-4862/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-4862/, https://www.rapid7.com/db/vulnerabilities/vmsa-2012-0006-cve-2011-4862/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-4862/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2011-4862/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-1852/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-1853/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: BSD
2011
FreeBSD Telnet Service Encryption Key ID Buffer Overflow
This module exploits a buffer overflow in the encryption option handler of the FreeBSD telnet service.
Mitigation:
Upgrade to the latest version of FreeBSD