PT-2012-2916 · Xinetd+3 · Xinetd+3

Thomas Swan

·

Published

2012-06-04

·

Updated

2024-06-15

·

CVE-2012-0862

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xinetd versions prior to 2.3.15
Description The issue allows remote attackers to bypass intended access restrictions. This occurs because builtins.c in Xinetd does not check the service type when the tcpmux-server service is enabled, exposing all enabled services. Attackers can exploit this by sending a request to the tcpmux port.
Recommendations For versions prior to 2.3.15, update to version 2.3.15 or later to resolve the issue. As a temporary workaround, consider disabling the tcpmux-server service to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_0499
CVE-2012-0862
OPENSUSE-SU-2024:10323-1
RHSA-2013:0499
RHSA-2013:1302
RHSA-2013_0499
RHSA-2013_1302
SUSE-SU-2014_0466-1
SUSE-SU-2014_0871-1

Affected Products

Centos
Red Hat
Suse
Xinetd