CVE-2012-0862: Xinetd
Medium severity, CVSS 4.3. EPSS: 2.7% chance of exploitation in the next 30 days.
builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.
Affected products
- Xinetd Xinetd: up to and including 2.3.14; version 2.3.5 only; version 2.3.6 only; version 2.3.7 only; version 2.3.8 only; version 2.3.9 only; …
Published 2012-06-04. Last modified 2026-06-16.