Bug 1213295 (CVE-1999-0636) - VUL-0: CVE-1999-0636: xinetd: The discard service is running.
Summary: VUL-0: CVE-1999-0636: xinetd: The discard service is running.
Status: RESOLVED WONTFIX
Alias: CVE-1999-0636
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Critical
Target Milestone: ---
Assignee: package coldpool
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/6678/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-07-13 15:03 UTC by Marcus Meissner
Modified: 2023-07-13 15:52 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2023-07-13 15:03:36 UTC
CVE-1999-0636

The discard service is running.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0636
https://www.cve.org/CVERecord?id=CVE-1999-0636
Comment 1 Marcus Meissner 2023-07-13 15:05:27 UTC
Note that discard is a service which would be served by either inetd or xinetd.

In our xinetd configurations the service is default disabled.


There is not much more information about this CVE, and how it would be exploitable.

The only current way I see is that it can be used to check for system presence,  but this would usually also be possible via SYN scans, ICMP pings or similar methods.
Comment 2 Marcus Meissner 2023-07-13 15:33:02 UTC
close to the original location here the CVE discussion:


https://cve.mitre.org/data/board/archives/1999-08/msg00007.html
Comment 3 Marcus Meissner 2023-07-13 15:34:34 UTC
discussion on whether to assign CVEs:

https://cve.mitre.org/data/board/archives/1999-08/msg00004.html
Comment 4 Marcus Meissner 2023-07-13 15:52:30 UTC
closing this CVE archeology topic.