CVE-2013-4342
Summary
| CVE | CVE-2013-4342 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-10 00:55:14 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 5 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Application | Xinetd | Xinetd | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2013-4342: xinetd ignores user and group directives for TCPMUX services by octurite · Pull Request #10 · xinetd-org/xinetd · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| xinetd: Privilege escalation (GLSA 201611-06) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| 1006100 – (CVE-2013-4342) CVE-2013-4342 xinetd: ignores user and group directives for tcpmux services | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Exploit, Patch |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| access.redhat.com | CVE-2013-4342 | MITRE | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 905558 Common Base Linux Mariner (CBL-Mariner) Security Update for xinetd (13601)
- 905560 Common Base Linux Mariner (CBL-Mariner) Security Update for xinetd (13592)
- 906764 Common Base Linux Mariner (CBL-Mariner) Security Update for xinetd (13592-1)
- 906795 Common Base Linux Mariner (CBL-Mariner) Security Update for xinetd (13601-1)