Vulnerability Name: | CVE-2001-1322 (CCN-6657) | ||||||||
Assigned: | 2001-06-04 | ||||||||
Published: | 2001-06-04 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask. | ||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-01:47 xinetd contains multiple vulnerabilities Source: MITRE Type: CNA CVE-2001-1322 Source: CONECTIVA Type: UNKNOWN CLA-2001:404 Source: CCN Type: Conectiva Linux Announcement CLSA-2001:404 xinetd Source: IMMUNIX Type: UNKNOWN IMNX-2001-70-024-01 Source: CCN Type: Immunix OS Security Advisory IMNX-2001-70-029-01 xinetd Source: CCN Type: RHSA-2001-075 Updated xinetd package available for Red Hat Linux 7 and 7.1 Source: DEBIAN Type: UNKNOWN DSA-063 Source: DEBIAN Type: DSA-063 xinetd -- change default umask Source: XF Type: Vendor Advisory xinetd-insecure-permissions(6657) Source: MANDRAKE Type: UNKNOWN MDKSA-2001:055 Source: ENGARDE Type: Vendor Advisory ESA-20010621-01 Source: CCN Type: EnGarde Secure Linux Security Advisory ESA-20010621-01 xinetd Source: CCN Type: OSVDB ID: 1854 xinetd Insecure Default Umask Arbitrary File Modification Source: REDHAT Type: UNKNOWN RHSA-2001:075 Source: BID Type: UNKNOWN 2826 Source: CCN Type: BID-2826 xinetd Insecure Default Umask Vulnerability Source: CCN Type: SuSE Security Announcement SuSE-SA:2001:022 xinetd Source: XF Type: UNKNOWN xinetd-insecure-permissions(6657) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |