Bug 844230 (CVE-2013-4342) - VUL-0: CVE-2013-4342: xinetd: ignores user and group directives for tcpmux services
Summary: VUL-0: CVE-2013-4342: xinetd: ignores user and group directives for tcpmux se...
Status: RESOLVED FIXED
Alias: CVE-2013-4342
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Major
Target Milestone: ---
Deadline: 2014-07-04
Assignee: Tomas Cech
QA Contact: Security Team bot
URL:
Whiteboard: maint:running:56423:moderate maint:re...
Keywords: DSLA_REQUIRED, DSLA_SOLUTION_PROVIDED
Depends on: 855685
Blocks:
  Show dependency treegraph
 
Reported: 2013-10-07 07:19 UTC by Marcus Meissner
Modified: 2018-10-19 18:13 UTC (History)
8 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-10-07 07:19:02 UTC
via rh bugzilla

CVE-2013-4342

If a tcpmux service is enabled, the user and group directives are ignored and the service always runs as root. Verified in the xinetd codebase and affects all active versions of RHEL and Fedora.  Without the fix for CVE-2012-0862, previously exposed non-tcpmux services could run as root bypassing their respective user and group restrictions.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4342
https://bugzilla.redhat.com/show_bug.cgi?id=1006100
Comment 1 Swamp Workflow Management 2013-10-11 07:41:17 UTC
bugbot adjusting priority
Comment 3 Sebastian Krahmer 2013-12-18 13:35:06 UTC
Sorry for late reply. Did the situation changed meanwhile,
so we can take everything from upstream?
Comment 4 Michal Vyskocil 2013-12-19 14:40:28 UTC
No, the last commit to xinetd's branch is year old - I'd recommend to use the patch from a pull request ...
Comment 5 Marcus Meissner 2014-01-08 16:20:49 UTC
yes, lets do that. looks simple enough.
Comment 13 Swamp Workflow Management 2014-03-31 10:04:24 UTC
Update released for: xinetd, xinetd-debuginfo
Products:
SLE-DEBUGINFO 10-SP3-TERADATA (x86_64)
SLE-SERVER 10-SP3-TERADATA (x86_64)
Comment 14 Swamp Workflow Management 2014-03-31 10:04:51 UTC
Update released for: xinetd
Products:
SUSE-CORE 9-SP3-TERADATA (x86_64)
Comment 15 Swamp Workflow Management 2014-03-31 10:05:28 UTC
Update released for: xinetd, xinetd-debuginfo, xinetd-debugsource
Products:
SLE-DEBUGINFO 11-SP1-TERADATA (x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
Comment 17 Vítězslav Čížek 2014-03-31 11:49:57 UTC
Factory and SLE12 were fixed.
openSUSE update submitted as well.
Comment 18 Bernhard Wiedemann 2014-03-31 12:00:25 UTC
This is an autogenerated message for OBS integration:
This bug (844230) was mentioned in
https://build.opensuse.org/request/show/228309 13.1+12.3 / xinetd
Comment 19 Marcus Meissner 2014-03-31 15:40:25 UTC
okay, all stuff submitted
Comment 20 Swamp Workflow Management 2014-03-31 15:47:47 UTC
Update released for: xinetd, xinetd-debuginfo, xinetd-debugsource
Products:
SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP3 (i386, x86_64)
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 21 Swamp Workflow Management 2014-03-31 19:04:32 UTC
SUSE-SU-2014:0466-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 762294,844230,855685
CVE References: CVE-2012-0862,CVE-2013-4342
Sources used:
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    xinetd-2.3.14-130.133.1
SUSE Linux Enterprise Server 11 SP3 (src):    xinetd-2.3.14-130.133.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    xinetd-2.3.14-130.133.1
Comment 22 Bernhard Wiedemann 2014-04-02 13:00:16 UTC
This is an autogenerated message for OBS integration:
This bug (844230) was mentioned in
https://build.opensuse.org/request/show/228736 Factory / xinetd
Comment 23 Swamp Workflow Management 2014-04-08 19:05:31 UTC
openSUSE-SU-2014:0494-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 726737,762294,844230,855685
CVE References: CVE-2012-0862,CVE-2013-4342
Sources used:
openSUSE 11.4 (src):    xinetd-2.3.14-155.1
Comment 24 Swamp Workflow Management 2014-04-11 14:05:34 UTC
openSUSE-SU-2014:0517-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 762294,844230,855685
CVE References: CVE-2012-0862,CVE-2013-4342
Sources used:
openSUSE 13.1 (src):    xinetd-2.3.15-2.8.1
openSUSE 12.3 (src):    xinetd-2.3.14-163.4.1
Comment 37 Swamp Workflow Management 2014-06-20 12:48:16 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-07-04.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/57970
Comment 38 Marcus Meissner 2014-06-20 12:57:41 UTC
*** Bug 882917 has been marked as a duplicate of this bug. ***
Comment 39 stanislav tokos 2014-06-30 12:56:32 UTC
PTF for SLES11-SP1 is available there:

https://ptf.suse.com/56c18f00d531d259c8db862e82b9eee6/sles11-sp1/7086/x86_64/20140630

-------------------------------------------------------------------
Mon Jun 30 14:48:35 CEST 2014 - stokos@suse.de

- xinetd-2.3.14-bnc844230.patch
  (bnc#882917, bnc#844230, CVE-2013-4342) 

-------------------------------------------------------------------

Please, give me feedback.
Comment 40 stanislav tokos 2014-06-30 12:57:49 UTC
I am sorry it should be in the bug 882917.
Comment 41 Swamp Workflow Management 2014-07-04 19:48:02 UTC
Update released for: xinetd, xinetd-debuginfo, xinetd-debugsource
Products:
SLE-DEBUGINFO 11-SP1 (i386, s390x, x86_64)
SLE-SERVER 11-SP1-LTSS (i386, s390x, x86_64)
Comment 42 Swamp Workflow Management 2014-07-04 19:49:20 UTC
Update released for: xinetd, xinetd-debuginfo
Products:
SLE-SERVER 10-SP3-LTSS (i386, s390x, x86_64)
Comment 43 Swamp Workflow Management 2014-07-04 19:55:29 UTC
Update released for: xinetd, xinetd-debuginfo, xinetd-debugsource
Products:
SLE-DEBUGINFO 11-SP2 (i386, s390x, x86_64)
SLE-SERVER 11-SP2-LTSS (i386, s390x, x86_64)
Comment 44 Swamp Workflow Management 2014-07-04 20:46:18 UTC
Update released for: xinetd, xinetd-debuginfo
Products:
SLE-SERVER 10-SP4-LTSS (i386, s390x, x86_64)
Comment 45 Swamp Workflow Management 2014-07-05 00:04:41 UTC
SUSE-SU-2014:0871-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 762294,844230
CVE References: CVE-2012-0862,CVE-2013-4342
Sources used:
SUSE Linux Enterprise Server 11 SP2 LTSS (src):    xinetd-2.3.14-130.133.1
SUSE Linux Enterprise Server 11 SP1 LTSS (src):    xinetd-2.3.14-130.133.1
SUSE Linux Enterprise Server 10 SP4 LTSS (src):    xinetd-2.3.14-14.12.1
SUSE Linux Enterprise Server 10 SP3 LTSS (src):    xinetd-2.3.14-14.12.1
Comment 46 Victor Pereira 2015-07-24 09:12:06 UTC
released, closed and fixed.