Xinetd Open File Descriptor Denial Of Service Vulnerability
BID:5458
Info
Xinetd Open File Descriptor Denial Of Service Vulnerability
| Bugtraq ID: | 5458 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 13 2002 12:00AM |
| Updated: | Aug 13 2002 12:00AM |
| Credit: | This vulnerability was discovered during an audit of Xinetd by Solar Designer <[email protected]>. |
| Vulnerable: |
Xinetd Xinetd 2.3.6 Xinetd Xinetd 2.3.5 Xinetd Xinetd 2.3.4 HP Secure OS software for Linux 1.0 Conectiva Linux Enterprise Edition 1.0 |
| Not Vulnerable: |
Xinetd Xinetd 2.3.7 |
Discussion
Xinetd Open File Descriptor Denial Of Service Vulnerability
xinetd is vulnerable to a denial of service condition due to inadvertent file descriptor inheritance.
The vulnerability is the result of file descriptors for the signal pipe being inherited by child processes launched by xinetd. This may result in a malicious attacker access to pipes associated with xinetd thus having the ability to communicate with xinetd.
xinetd is vulnerable to a denial of service condition due to inadvertent file descriptor inheritance.
The vulnerability is the result of file descriptors for the signal pipe being inherited by child processes launched by xinetd. This may result in a malicious attacker access to pipes associated with xinetd thus having the ability to communicate with xinetd.
Exploit / POC
Xinetd Open File Descriptor Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Xinetd Open File Descriptor Denial Of Service Vulnerability
Solution:
Gentoo Linux recommends that all users who are running sys-apps/xinetd-2.3.5 and earlier update their systems by running the following commands:
emerge rsync
emerge xinetd
emerge clean
MandrakeSoft has stated that Linux Mandrake 8.2 is affected. Fixes are available for i586 and PPC platforms. Further details are available in the referenced advisory.
FreeBSD has released upgrades. Users are advised to upgrade their Ports
collection and reinstall the affected port.
RedHat has released an advisory. Fixes are available for i386 and alpha platforms.
Conectiva has also released an advisory (CLSA-2003:790) including a fix to address this issue in CLEE 1.0.
HP has released bulletin HPSBTL0211-0076 to provide fixes for this issue.
The following fixes are available:
HP Secure OS software for Linux 1.0
Conectiva Linux Enterprise Edition 1.0
Xinetd Xinetd 2.3.4
Xinetd Xinetd 2.3.5
Xinetd Xinetd 2.3.6
Solution:
Gentoo Linux recommends that all users who are running sys-apps/xinetd-2.3.5 and earlier update their systems by running the following commands:
emerge rsync
emerge xinetd
emerge clean
MandrakeSoft has stated that Linux Mandrake 8.2 is affected. Fixes are available for i586 and PPC platforms. Further details are available in the referenced advisory.
FreeBSD has released upgrades. Users are advised to upgrade their Ports
collection and reinstall the affected port.
RedHat has released an advisory. Fixes are available for i386 and alpha platforms.
Conectiva has also released an advisory (CLSA-2003:790) including a fix to address this issue in CLEE 1.0.
HP has released bulletin HPSBTL0211-0076 to provide fixes for this issue.
The following fixes are available:
HP Secure OS software for Linux 1.0
-
HP HPTL_00032
http://itrc.hp.com
Conectiva Linux Enterprise Edition 1.0
-
Conectiva xinetd-2.3.11-26.i586.rpm
ftp://ul.conectiva.com.br/updates/1.0/RPMS.core/xinetd-2.3.11-26.i586. rpm
Xinetd Xinetd 2.3.4
-
Debian xinetd_2.3.4-1.2_alpha.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _alpha.deb -
Debian xinetd_2.3.4-1.2_arm.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _arm.deb -
Debian xinetd_2.3.4-1.2_hppa.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _hppa.deb -
Debian xinetd_2.3.4-1.2_i386.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _i386.deb -
Debian xinetd_2.3.4-1.2_ia64.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _ia64.deb -
Debian xinetd_2.3.4-1.2_m68k.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _m68k.deb -
Debian xinetd_2.3.4-1.2_mips.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _mips.deb -
Debian xinetd_2.3.4-1.2_mipsel.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _mipsel.deb -
Debian xinetd_2.3.4-1.2_powerpc.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _powerpc.deb -
Debian xinetd_2.3.4-1.2_s390.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _s390.deb -
Debian xinetd_2.3.4-1.2_sparc.deb
http://security.debian.org/pool/updates/main/x/xinetd/xinetd_2.3.4-1.2 _sparc.deb -
Xinetd xinetd-2.3.7.tar.gz
http://synack.net/xinetd/xinetd-2.3.7.tar.gz
Xinetd Xinetd 2.3.5
-
Xinetd xinetd-2.3.7.tar.gz
http://synack.net/xinetd/xinetd-2.3.7.tar.gz
Xinetd Xinetd 2.3.6
-
MandrakeSoft xinetd-2.3.7-1.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft xinetd-2.3.7-1.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft xinetd-ipv6-2.3.7-1.1mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft xinetd-ipv6-2.3.7-1.1mdk.ppc.rpm
http://www.mandrakesecure.net/en/ftp.php -
Red Hat xinetd-2.3.7-4.7x.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/xinetd-2.3.7-4.7x.alpha.rpm -
Red Hat xinetd-2.3.7-4.7x.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/xinetd-2.3.7-4.7x.alpha.rpm -
Red Hat xinetd-2.3.7-4.7x.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/xinetd-2.3.7-4.7x.i386.rpm -
Red Hat xinetd-2.3.7-4.7x.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/xinetd-2.3.7-4.7x.i386.rpm -
Red Hat xinetd-2.3.7-4.7x.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/xinetd-2.3.7-4.7x.i386.rpm -
Red Hat xinetd-2.3.7-4.7x.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/xinetd-2.3.7-4.7x.i386.rpm -
Red Hat xinetd-2.3.7-4.7x.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/xinetd-2.3.7-4.7x.ia64.rpm -
Red Hat xinetd-2.3.7-4.7x.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/xinetd-2.3.7-4.7x.ia64.rpm -
Red Hat xinetd-2.3.7-5.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/xinetd-2.3.7-5.i386.rpm -
Xinetd xinetd-2.3.7.tar.gz
http://synack.net/xinetd/xinetd-2.3.7.tar.gz
References
Xinetd Open File Descriptor Denial Of Service Vulnerability
References:
References:
- CLSA-2003:790 (Conectiva)
- Xinetd Homepage (Xinetd)