CVE-2013-4342
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 6.39% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- xinetd/xinetd · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-1409.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1006100Exploit, Patch
- https://github.com/xinetd-org/xinetd/pull/10
- https://security.gentoo.org/glsa/201611-06
- http://rhn.redhat.com/errata/RHSA-2013-1409.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1006100Exploit, Patch
- https://github.com/xinetd-org/xinetd/pull/10
- https://security.gentoo.org/glsa/201611-06
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.