CVE-2013-4342 describes a privilege escalation vulnerability in xinetd, affecting Red Hat Enterprise Linux and xinetd itself. The flaw stems from xinetd failing to enforce user and group configurations for TCPMUX services, leading to these services running as root. This significantly increases the risk of remote attackers gaining root privileges if another vulnerability exists within a TCPMUX service. With a CVSS score of 7.6, this vulnerability is rated as high severity due to its network-based attack vector and complete compromise of confidentiality, integrity, and availability, despite requiring high attack complexity. The EPSS score of 0.15271 indicates a moderate likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:xinetd:xinetd:-:*:*:*:*:*:*:* | ||
5CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2013-4342
Jun 11, 2024xinetd does not enforce the user and group configuration directives for TCPMUX services which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.
Oct 2, 2013xinetd: ignores user and group directives for tcpmux services
Aug 23, 2005