CVE-2001-1322: Low severity Xinetd Xinetd vulnerability
Published Jul 10, 2001
·Updated
xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask.
Affected Software
16 affected components
Xinetd Xinetd=2.1.8.9_pre15
Xinetd Xinetd=2.1.8.9_pre10
Xinetd Xinetd=2.1.8.9_pre5
Xinetd Xinetd=2.1.8.8
Xinetd Xinetd=2.1.8.9_pre3
Xinetd Xinetd=2.1.8.9_pre9
Xinetd Xinetd=2.1.8.9_pre1
Xinetd Xinetd=2.1.8.9_pre8
Xinetd Xinetd=2.1.8.8_pre3
Xinetd Xinetd=2.1.8.9_pre14
Xinetd Xinetd=2.1.8.9_pre2
Xinetd Xinetd=2.1.8.9_pre13
Xinetd Xinetd=2.1.8.9_pre12
Xinetd Xinetd=2.1.8.9_pre11
Xinetd Xinetd=2.1.8.9_pre7
Xinetd Xinetd=2.1.8.9_pre4
Event History
Jul 10, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1322?
The severity of CVE-2001-1322 is considered moderate due to the potential unauthorized access to sensitive files.
2
How do I fix CVE-2001-1322?
To fix CVE-2001-1322, configure xinetd to use a more secure umask value for newly created files.
3
Who is affected by CVE-2001-1322?
CVE-2001-1322 affects users of xinetd versions 2.1.8 and earlier, particularly in SUSE distributions.
4
What can attackers do with CVE-2001-1322?
Attackers can exploit CVE-2001-1322 to read or modify files created by applications running under xinetd.
5
Is there a patch available for CVE-2001-1322?
Yes, a patch is available for CVE-2001-1322 and users should update to a more secure version of xinetd.