Vulnerability CVE-2013-4342


Published: 2013-10-09   Modified: 2013-10-11

Description:
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:H/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.6/10
10/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Xinetd -> Xinetd 
Redhat -> Enterprise linux 

 References:
http://rhn.redhat.com/errata/RHSA-2013-1409.html
https://bugzilla.redhat.com/show_bug.cgi?id=1006100
https://github.com/xinetd-org/xinetd/pull/10
https://security.gentoo.org/glsa/201611-06

Copyright 2024, cxsecurity.com

 

Back to Top