CVE-2001-1322
Summary
| CVE | CVE-2001-1322 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2001-07-10 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask. |
Risk And Classification
Primary CVSS: v2.0 3.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xinetd | Xinetd | 2.1.8.8 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.8_pre3 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre1 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre10 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre11 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre12 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre13 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre14 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre15 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre2 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre3 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre4 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre5 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre7 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre8 | All | All | All |
| Application | Xinetd | Xinetd | 2.1.8.9_pre9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.linux-mandrake.com/en/security/2001/MDKSA-2001-055.php3 | af854a3a-2127-422b-91ae-364da2661108 | www.linux-mandrake.com | |
| Debian GNU/Linux -- Security Information -- DSA-063-1 xinetd | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| xinetd Insecure Default Umask Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ISS X-Force Database: | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Vendor Advisory |
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | |
| LinuxSecurity.com: EnGarde: 'xinetd' fixes | af854a3a-2127-422b-91ae-364da2661108 | www.linuxsecurity.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-024-01 | af854a3a-2127-422b-91ae-364da2661108 | download.immunix.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.