Vulnerabilities > CVE-2001-0763
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function.
Vulnerable Configurations
Exploit-Db
description | Xinetd 2.1.8 Buffer Overflow Vulnerability. CVE-2001-0763. Remote exploit for linux platform |
id | EDB-ID:20908 |
last seen | 2016-02-02 |
modified | 2001-06-28 |
published | 2001-06-28 |
reporter | qitest1 |
source | https://www.exploit-db.com/download/20908/ |
title | Xinetd 2.1.8 - Buffer Overflow Vulnerability |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-063.NASL |
description | zen-parse reported on bugtraq that there is a possible buffer overflow in the logging code from xinetd. This could be triggered by using a fake identd that returns special replies when xinetd does an ident request. Another problem is that xinetd sets it umask to 0. As a result any programs that xinetd start that are not careful with file permissions will create world-writable files. Both problems have been fixed in version 2.1.8.8.p3-1.1. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14900 |
published | 2004-09-29 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14900 |
title | Debian DSA-063-1 : xinetd - change default umask |
code |
|
Redhat
advisories |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2001-06/0064.html
- http://www.debian.org/security/2001/dsa-063
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000404
- http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-024-01
- http://www.linuxsecurity.com/advisories/other_advisory-1469.html
- http://www.ciac.org/ciac/bulletins/l-104.shtml
- http://www.redhat.com/support/errata/RHSA-2001-075.html
- http://www.securityfocus.com/bid/2840
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6670