Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv4c-6fpc-r32q

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.

builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.

EPSS

Процентиль: 66%
0.00535
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 13 лет назад

builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.

redhat
больше 13 лет назад

builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.

nvd
около 13 лет назад

builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.

debian
около 13 лет назад

builtins.c in Xinetd before 2.3.15 does not check the service type whe ...

oracle-oval
почти 12 лет назад

ELSA-2013-1302: xinetd security and bug fix update (LOW)

EPSS

Процентиль: 66%
0.00535
Низкий

Дефекты

CWE-20