CVE Vulnerabilities

CVE-2012-2653

Published: Jul 12, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
3.3 MODERATE
AV:A/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.

Affected Software

NameVendorStart VersionEnd Version
ArpwatchLawrence_berkeley_national_laboratory2.1a15 (including)2.1a15 (including)
ArpwatchUbuntuhardy*
ArpwatchUbuntulucid*
ArpwatchUbuntunatty*
ArpwatchUbuntuoneiric*
ArpwatchUbuntuprecise*
ArpwatchUbuntuupstream*

References