LWN.net Logo

Mageia alert MGASA-2012-0129 (arpwatch)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2012-0129: arpwatch-2.1a15-8.1.mga1 (1/core), arpwatch-2.1a15-9.1.mga2 (2/core)
Date:  Wed, 27 Jun 2012 16:31:29 +0200
Message-ID:  <20120627143129.GA888@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2012-0129 Date: June 27th, 2012 Affected releases: 1, 2 Description: Updated arpwatch package fixes security vulnerability: Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at least in Red Hat and Debian distributions) in order to make it drop root privileges would fail to do so and instead add the root group to the list of the daemon uses (CVE-2012-2653). Updated Packages: Mageia 1: arpwatch-2.1a15-8.1.mga1 Mageia 2: arpwatch-2.1a15-9.1.mga2 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2653 http://www.debian.org/security/2012/dsa-2481 https://bugs.mageia.org/show_bug.cgi?id=6329 https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds