CVE-2012-0862: Xinetd

Medium severity, CVSS 4.3. EPSS: 2.7% chance of exploitation in the next 30 days.

builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.

Affected products

  • Xinetd Xinetd: up to and including 2.3.14; version 2.3.5 only; version 2.3.6 only; version 2.3.7 only; version 2.3.8 only; version 2.3.9 only; …

Published 2012-06-04. Last modified 2026-06-16.