VDB
CVE-2012-0862
CVE-2012-0862
PUBLISHED
CVSS 4.300000190734863 MEDIUM
builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.
EPSS 0.54% · 67.8th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
0.54%
67.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| xinetd | xinetd | 2.3.5, 0, 2.3.6 |
| n/a | n/a | n/a |
Timeline
- Jun 4, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 1027050 vdb
- [oss-security] 20120509 CVE-2012-0862 assignment notification: xinetd enables unintentional services over tcpmux port mailing-list
- FEDORA-2012-8041 vendor-advisory
- 81774 vdb
- xinetd-tcpmux-weak-security(75965) vdb
- https://bugzilla.redhat.com/attachment.cgi?id=583311 url
- RHSA-2013:1302 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=790940 url
- FEDORA-2012-8061 vendor-advisory
- [oss-security] 20120510 Re: CVE-2012-0862 assignment notification: xinetd enables unintentional services over tcpmux port mailing-list
- 53720 vdb
- MDVSA-2012:155 vendor-advisory
- http://www.xinetd.org/#changes url
- https://nvd.nist.gov/vuln/detail/CVE-2012-0862 advisory