Debian Security Advisory
DSA-2481-1 arpwatch -- fails to drop supplementary groups
- Date Reported:
- 02 Jun 2012
- Affected Packages:
- arpwatch
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 674715.
In Mitre's CVE dictionary: CVE-2012-2653. - More information:
-
Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at least in Red Hat and Debian distributions) in order to make it drop root privileges would fail to do so and instead add the root group to the list of the daemon uses.
For the stable distribution (squeeze), this problem has been fixed in version 2.1a15-1.1+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in version 2.1a15-1.2.
For the unstable distribution (sid), this problem has been fixed in version 2.1a15-1.2.
We recommend that you upgrade your arpwatch packages.