CVE Vulnerabilities

CVE-2012-2653

Published: Jul 12, 2012 | Modified: Nov 28, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
3.3 MODERATE
AV:A/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.

Affected Software

Name Vendor Start Version End Version
Arpwatch Lawrence_berkeley_national_laboratory 2.1a15 (including) 2.1a15 (including)
Arpwatch Ubuntu hardy *
Arpwatch Ubuntu lucid *
Arpwatch Ubuntu natty *
Arpwatch Ubuntu oneiric *
Arpwatch Ubuntu precise *
Arpwatch Ubuntu upstream *

References