PT-2012-2916 · Xinetd+3 · Xinetd+3

Thomas Swan

·

Publicado

2012-06-04

·

Atualizado

2024-06-15

·

CVE-2012-0862

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xinetd versions prior to 2.3.15
Description The issue allows remote attackers to bypass intended access restrictions. This occurs because builtins.c in Xinetd does not check the service type when the tcpmux-server service is enabled, exposing all enabled services. Attackers can exploit this by sending a request to the tcpmux port.
Recommendations For versions prior to 2.3.15, update to version 2.3.15 or later to resolve the issue. As a temporary workaround, consider disabling the tcpmux-server service to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_0499
CVE-2012-0862
OPENSUSE-SU-2024:10323-1
RHSA-2013:0499
RHSA-2013:1302
RHSA-2013_0499
RHSA-2013_1302
SUSE-SU-2014_0466-1
SUSE-SU-2014_0871-1

Produtos afetados

Centos
Red Hat
Suse
Xinetd