{"api_version":"1","generated_at":"2026-07-23T07:14:45+00:00","cve":"CVE-2013-4342","urls":{"html":"https://cve.report/CVE-2013-4342","api":"https://cve.report/api/cve/CVE-2013-4342.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-4342","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-4342"},"summary":{"title":"CVE-2013-4342","description":"xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.","state":"PUBLISHED","assigner":"redhat","published_at":"2013-10-10 00:55:14","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.6","severity":"","vector":"AV:N/AC:H/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:C/I:C/A:C","baseScore":7.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://github.com/xinetd-org/xinetd/pull/10","name":"https://github.com/xinetd-org/xinetd/pull/10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CVE-2013-4342: xinetd ignores user and group directives for TCPMUX services by octurite · Pull Request #10 · xinetd-org/xinetd · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-1409.html","name":"http://rhn.redhat.com/errata/RHSA-2013-1409.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201611-06","name":"https://security.gentoo.org/glsa/201611-06","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"xinetd: Privilege escalation  (GLSA 201611-06) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1006100","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1006100","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"1006100 – (CVE-2013-4342) CVE-2013-4342 xinetd: ignores user and group directives for tcpmux services","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2013:1409","name":"MISC:https://access.redhat.com/errata/RHSA-2013:1409","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2013-4342","name":"MISC:https://access.redhat.com/security/cve/CVE-2013-4342","refsource":"MITRE","tags":[],"title":"access.redhat.com | CVE-2013-4342","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-4342","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4342","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"4342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xinetd","cpe5":"xinetd","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2013-4342","qid":"905558","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for xinetd (13601)"},{"cve":"CVE-2013-4342","qid":"905560","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for xinetd (13592)"},{"cve":"CVE-2013-4342","qid":"906764","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for xinetd (13592-1)"},{"cve":"CVE-2013-4342","qid":"906795","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for xinetd (13601-1)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T16:38:01.956Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"GLSA-201611-06","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201611-06"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1006100"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/xinetd-org/xinetd/pull/10"},{"name":"RHSA-2013:1409","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-1409.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-09-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-06-30T16:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"GLSA-201611-06","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201611-06"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1006100"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/xinetd-org/xinetd/pull/10"},{"name":"RHSA-2013:1409","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-1409.html"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2013-4342","datePublished":"2013-10-10T00:00:00.000Z","dateReserved":"2013-06-12T00:00:00.000Z","dateUpdated":"2024-08-06T16:38:01.956Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-10-10 00:55:14","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:C/I:C/A:C","baseScore":7.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":4.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:xinetd:xinetd:-:*:*:*:*:*:*:*","matchCriteriaId":"43ECBCF4-C433-4177-A0B4-6E560ED2B720"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*","matchCriteriaId":"AA9B3CC0-DF1C-4A86-B2A3-A9D428A5A6E6"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","matchCriteriaId":"2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"4342","Ordinal":"1","Title":"CVE-2013-4342","CVE":"CVE-2013-4342","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"4342","Ordinal":"1","NoteData":"xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.","Type":"Description","Title":"CVE-2013-4342"},{"CveYear":"2013","CveId":"4342","Ordinal":"2","NoteData":"2013-10-09","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"4342","Ordinal":"3","NoteData":"2017-06-30","Type":"Other","Title":"Modified"}]}}}