CVE-2012-0862

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
04/06/2012
Last modified:
11/04/2025

Description

builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xinetd:xinetd:*:*:*:*:*:*:*:* 2.3.14 (including)
cpe:2.3:a:xinetd:xinetd:2.3.5:*:*:*:*:*:*:*
cpe:2.3:a:xinetd:xinetd:2.3.6:*:*:*:*:*:*:*
cpe:2.3:a:xinetd:xinetd:2.3.7:*:*:*:*:*:*:*
cpe:2.3:a:xinetd:xinetd:2.3.8:*:*:*:*:*:*:*
cpe:2.3:a:xinetd:xinetd:2.3.9:*:*:*:*:*:*:*
cpe:2.3:a:xinetd:xinetd:2.3.10:*:*:*:*:*:*:*
cpe:2.3:a:xinetd:xinetd:2.3.11:*:*:*:*:*:*:*
cpe:2.3:a:xinetd:xinetd:2.3.12:*:*:*:*:*:*:*
cpe:2.3:a:xinetd:xinetd:2.3.13:*:*:*:*:*:*:*