SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  Xinetd Vendors:  Xinetd.org
Xinetd File Descriptor Leak May Allow a Remote User to Cause the Daemon to Crash
SecurityTracker Alert ID:  1005143
CVE Reference:  CVE-2002-0871   (Links to External Site)
Updated:  Feb 21 2004
Original Entry Date:  Aug 27 2002
Impact:  Denial of service via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): 2.3.4 - 2.3.6
Description:  A denial of service vulnerability was reported in xinetd. A remote user may be able to cause xinetd to crash.

It is reported that there is a file descriptor leak in xinetd. A signal pipe could leak into child processes.

No further details were provided.

The vendor credits Solar Designer with reporting this flaw.

Impact:  A remote user may be able to cause the daemon to crash.
Solution:  The vendor has released a fixed version (2.3.7), available at:

http://www.xinetd.org/

Vendor URL:  www.xinetd.org/ (Links to External Site)
Cause:  Resource error, State error
Underlying OS:  Linux (Any), UNIX (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Aug 27 2002 (Mandrake Issues Fix) Re: Xinetd File Descriptor Leak May Allow a Remote User to Cause the Daemon to Crash   (Mandrake Linux Security Team <security@linux-mandrake.com>)
Mandrake has issued a fix.



 Source Message Contents

Date:  Tue, 27 Aug 2002 00:59:47 -0400
Subject:  Xinetd vulnerability

 

http://www.xinetd.org/

Version 2.3.7

A file descriptor leak was reported in versions 2.3.4 - 2.3.6 by Solar
Designer.  It is reported that the co-maintainer has indicated that the
worst case impact is that a local user could cause xinetd to crash.

>From the changelog:

* Added fixes or workarounds for issues introduced after 2.3.3 including
the signal pipe leak into child processes (a security hole). -Solar
Designer


 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC