Back to Database
Status published
Low
CVE-2001-1322
xinetd 2.1.8 and earlier runs with a default umask of...
Vulnerability Description
xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-1322
Credits & Attribution
No credits recorded in the NVD database.
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000404
- http://www.linuxsecurity.com/advisories/other_advisory-1469.html
- http://www.debian.org/security/2001/dsa-063
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-055.php3
- http://www.iss.net/security_center/static/6657.php
- http://www.securityfocus.com/bid/2826
- http://www.redhat.com/support/errata/RHSA-2001-075.html
- http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-024-01
More from xinetd
View All →CVE-2013-4342
xinetd does not enforce the user and group configuration directives...
High
7.6
CVE-2012-0862
builtins.c in Xinetd before 2.3.15 does not check the service...
Medium
4.3
CVE-2003-0211
Memory leak in xinetd 2.3.10 allows remote attackers to cause...
Medium
5
CVE-2002-0871
xinetd 2.3.4 leaks file descriptors for the signal pipe to...
Low
2.1
CVE-2001-1389
Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants...
High
7.5
Affected Vendor
xinetd
View all reports →Affected Software
xinetd
Vulnerable Versions:
2.1.8.8, 2.1.8.8_pre3, 2.1.8.9_pre1, 2.1.8.9_pre2, 2.1.8.9_pre3, 2.1.8.9_pre4, 2.1.8.9_pre5, 2.1.8.9_pre7, 2.1.8.9_pre8, 2.1.8.9_pre9, 2.1.8.9_pre10, 2.1.8.9_pre11, 2.1.8.9_pre12, 2.1.8.9_pre13, 2.1.8.9_pre14, 2.1.8.9_pre15
Timeline
Official Publish:
June 25th, 2002
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.