Total vulnerabilities in the database
builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.
Software | From | Fixed in |
---|---|---|
xinetd / xinetd | 2.3.7 | 2.3.7.x |
xinetd / xinetd | 2.3.8 | 2.3.8.x |
xinetd / xinetd | 2.3.10 | 2.3.10.x |
xinetd / xinetd | 2.3.6 | 2.3.6.x |
xinetd / xinetd | 2.3.11 | 2.3.11.x |
xinetd / xinetd | 2.3.5 | 2.3.5.x |
xinetd / xinetd | 2.3.12 | 2.3.12.x |
xinetd / xinetd | - | 2.3.14.x |
xinetd / xinetd | 2.3.13 | 2.3.13.x |
xinetd / xinetd | 2.3.9 | 2.3.9.x |