xinetd-2.3.14-38.AXS4

エラータID: AXSA:2013-131:01

Release date: 
Friday, March 8, 2013 - 14:35
Subject: 
xinetd-2.3.14-38.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Xinetd is a secure replacement for inetd, the Internet services daemon. Xinetd provides access control for all services based on the address of the remote host and/or on time of access and can prevent denial-of-access attacks. Xinetd provides extensive logging, has no limit on the number of server arguments, and lets you bind specific services to specific IP addresses on your host machine. Each service has its own specific configuration file for Xinetd; the files are located in the /etc/xinetd.d directory.

Security issues fixed with this release:

CVE-2012-0862
builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.

Fixed bugs:

• Previously, when xinetd was under heavy load, some file descriptors could remain open. The system log would also fill up with many messages, ending up taking a lot of space over time. This has been fixed.

• Previsouly, xinetd permanently disabled services when their CPS limit was reached, leading to potential failed bind operations when xinetd restarted the service. To fix this, services are now disabled only after 30 failures.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. xinetd-2.3.14-38.AXS4.src.rpm
    MD5: cfbdda12b3c25ae921a74072dd80c608
    SHA-256: eff340639bff8ca68928b141fb533b115d90728ab0b8dd8045d2f958e22c751a
    Size: 339.23 kB

Asianux Server 4 for x86
  1. xinetd-2.3.14-38.AXS4.i686.rpm
    MD5: 30c9f3ed83a3740d04001c973236190e
    SHA-256: d8d6cd356857f2d3bc1ad0ad09b5effa34b4c34293c795ba8da80599becea122
    Size: 121.62 kB

Asianux Server 4 for x86_64
  1. xinetd-2.3.14-38.AXS4.x86_64.rpm
    MD5: 4f2e88c9c493ba3b0200f12a4d16c4d9
    SHA-256: 91d1dd4a50c2d504c41e9fa455431459eeccc369d9a2b3c8979aa6b80f3ca05a
    Size: 120.49 kB