PT-2002-1013 · Xinetd · Xinetd

Published

2002-09-05

·

Updated

2016-12-08

·

CVE-2002-0871

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions xinetd versions 2.3.4 through 2.3.11
Description The issue affects the xinetd package, allowing for potential disruption of protected information. Exploitation can be done remotely or locally, depending on the context, and may lead to a denial of service. Specifically, in version 2.3.4, xinetd leaks file descriptors for the signal pipe to services launched by xinetd, which those services could exploit to cause a denial of service via the pipe.
Recommendations For xinetd version 2.3.4, consider restricting access to services launched by xinetd to prevent potential denial of service attacks via the signal pipe. For xinetd versions 2.3.7 through 2.3.11, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02935
BDU:2015-07775
BDU:2015-07980
CVE-2002-0871
DSA-151

Affected Products

Xinetd