[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2013-0499 -- Oracle xinetd

ID: oval:org.secpod.oval:def:1500005Date: (C)2013-03-20   (M)2023-12-07
Class: PATCHFamily: unix




An updated xinetd package that fixes one security issue and two bugs is nowavailable for Red Hat Enterprise Linux 6.The Red Hat Security Response Team has rated this update as having lowsecurity impact. A Common Vulnerability Scoring System base score,which gives a detailed severity rating, is available from the CVE link inthe References section. The xinetd package provides a secure replacement for inetd, the Internetservices daemon. xinetd provides access control for all services based onthe address of the remote host and/or on time of access, and can preventdenial-of-access attacks.When xinetd services are configured with the "TCPMUX" or "TCPMUXPLUS" type,and the tcpmux-server service is enabled, those services are accessible viaport 1. It was found that enabling the tcpmux-server service allowed every xinetd service, including those that arenot configured with the "TCPMUX" or "TCPMUXPLUS" type, to be accessible viaport 1. This could allow a remote attacker to bypass intended firewallrestrictions. Red Hat would like to thank Thomas Swan of FedEx for reporting this issue.This update also fixes the following bugs:* Prior to this update, a file descriptor array in the service.c sourcefile was not handled as expected. As a consequence, some of the descriptorsremained open when xinetd was under heavy load. Additionally, the systemlog was filled with a large number of messages that took up a lot of diskspace over time. This update modifies the xinetd code to handle the filedescriptors correctly and messages no longer fill the system log.* Prior to this update, services were disabled permanently when their CPSlimit was reached. As a consequence, a failed bind operation could occurwhen xinetd attempted to restart the service. This update adds additionallogic that attempts to restart the service. Now, the service is onlydisabled if xinetd cannot restart the service after 30 attempts.All users of xinetd are advised to upgrade to this updated package, whichcontains backported patches to correct these issues.

Platform:
Oracle Linux 6
Product:
xinetd
Reference:
ELSA-2013-0499
CVE-2012-0862
CVE    1
CVE-2012-0862
CPE    12
cpe:/a:xinetd:xinetd:2.3.13
cpe:/a:xinetd:xinetd:2.3.12
cpe:/a:xinetd:xinetd:2.3.11
cpe:/a:xinetd:xinetd:2.3.10
...

© SecPod Technologies