cbcvebase.
CVE-2013-4342
published 2013-10-10

CVE-2013-4342: xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for…

PriorityP345high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
6.39%
92.9th percentile
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianxinetd< xinetd 1:2.3.15-2 (bookworm)xinetd 1:2.3.15-2 (bookworm)
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatenterprise_linux
redhatenterprise_linux
xinetdxinetd>= 0 < 1:2.3.15-21:2.3.15-2
xinetdxinetd>= 0 < 1:2.3.15-21:2.3.15-2
xinetdxinetd>= 0 < 1:2.3.15-21:2.3.15-2
xinetdxinetd>= 0 < 1:2.3.15-21:2.3.15-2

CVSS provenance

nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
vendor_debian7.6HIGH
vendor_msrc7.6HIGH
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.