LWN.net Logo

xinetd: service disclosure flaw

Package(s):xinetd CVE #(s):CVE-2012-0862
Created:May 29, 2012 Updated:October 3, 2013
Description: From the Red Hat bugzilla:

Thomas Swan reported a service disclosure flaw in xinetd. xinetd allows for services to be configured with the TCPMUX or TCPMUXPLUS service types, which makes those services available on port 1, as per RFC 1078 [1], if the tcpmux-server service is enabled. When the tcpmux-server service is enabled, xinetd would expose _all_ enabled services via the tcpmux port, instead of just the configured service(s). This could allow a remote attacker to bypass firewall restrictions and access services via the tcpmux port.

Alerts:
Fedora FEDORA-2012-8061 2012-05-29
Fedora FEDORA-2012-8041 2012-05-29
Mandriva MDVSA-2012:155 2012-09-28
Mandriva MDVSA-2012:155-1 2012-10-02
Red Hat RHSA-2013:0499-02 2013-02-21
Oracle ELSA-2013-0499 2013-02-25
Scientific Linux SL-xine-20130228 2013-02-28
CentOS CESA-2013:0499 2013-03-09
Mandriva MDVSA-2013:057 2013-04-08
Red Hat RHSA-2013:1302-01 2013-09-30
Oracle ELSA-2013-1302 2013-10-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds