LWN.net Logo

arpwatch: privilege escalation

Package(s):arpwatch CVE #(s):CVE-2012-2653
Created:June 4, 2012 Updated:April 5, 2013
Description: From the Debian advisory:

Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at least in Red Hat and Debian distributions) in order to make it drop root privileges would fail to do so and instead add the root group to the list of the daemon uses.

Alerts:
Debian DSA-2481-1 2012-06-02
Debian DSA-2482-1 2012-06-02
Fedora FEDORA-2012-8677 2012-06-20
Fedora FEDORA-2012-8675 2012-06-20
Fedora FEDORA-2012-8702 2012-06-20
Mageia MGASA-2012-0129 2012-06-27
openSUSE openSUSE-SU-2012:0915-1 2012-07-25
Mandriva MDVSA-2012:113 2012-07-26
Mandriva MDVSA-2013:017 2013-04-04
Mandriva MDVSA-2013:030 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds