CVE-2001-0825: Buffer Overflow
Published Dec 6, 2001
·Updated
Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.
Affected Software
4 affected components
Xinetd Xinetd<=2.3.1
Xinetd Xinetd=2.1.8.8
Xinetd Xinetd=2.1.8.9
Xinetd Xinetd=2.3.0
Remediation
Patch Available
Patch Available
Event History
Dec 6, 2001
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0825?
CVE-2001-0825 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2001-0825?
To fix CVE-2001-0825, update xinetd to version 2.1.8.9 or later.
3
What software is affected by CVE-2001-0825?
The affected software includes xinetd versions prior to 2.1.8.8 and between 2.1.8.8 and 2.3.1.
4
What type of vulnerability is CVE-2001-0825?
CVE-2001-0825 is classified as a buffer overflow vulnerability.
5
Can CVE-2001-0825 be exploited remotely?
Yes, remote attackers can exploit CVE-2001-0825 given the conditions of a zero or less length argument.