CVE-2013-4342

NameCVE-2013-4342
Descriptionxinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs324678

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xinetd (PTS)buster, bookworm, bullseye1:2.3.15.3-1fixed
sid, trixie1:2.3.15.4-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xinetdsourcewheezy1:2.3.14-7.1+deb7u1
xinetdsource(unstable)1:2.3.15-2324678

Notes

[squeeze] - xinetd <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems