CVE-2013-4342

NameCVE-2013-4342
Descriptionxinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)
Debian Bugs324678

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xinetd (PTS)wheezy1:2.3.14-7.1+deb7u1fixed
jessie1:2.3.15-3fixed
stretch1:2.3.15-7fixed
buster, sid1:2.3.15.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xinetdsource(unstable)1:2.3.15-2high324678
xinetdsourcewheezy1:2.3.14-7.1+deb7u1high

Notes

[squeeze] - xinetd <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems