Name | CVE-2013-4342 |
Description | xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 324678 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
xinetd (PTS) | bookworm, bullseye | 1:2.3.15.3-1 | fixed |
| sid, trixie | 1:2.3.15.4-4 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
xinetd | source | wheezy | 1:2.3.14-7.1+deb7u1 | | | |
xinetd | source | (unstable) | 1:2.3.15-2 | | | 324678 |
Notes
[squeeze] - xinetd <no-dsa> (Minor issue)