DSA-2481-1 arpwatch -- fails to drop supplementary groups

Related Vulnerabilities: CVE-2012-2653  

Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at least in Red Hat and Debian distributions) in order to make it drop root privileges would fail to do so and instead add the root group to the list of the daemon uses. For the stable distribution (squeeze), this problem has been fixed in version 2.1a15-1.1+squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 2.1a15-1.2. For the unstable distribution (sid), this problem has been fixed in version 2.1a15-1.2. We recommend that you upgrade your arpwatch packages.

Debian Security Advisory

DSA-2481-1 arpwatch -- fails to drop supplementary groups

Date Reported:
02 Jun 2012
Affected Packages:
arpwatch
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 674715.
In Mitre's CVE dictionary: CVE-2012-2653.
More information:

Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at least in Red Hat and Debian distributions) in order to make it drop root privileges would fail to do so and instead add the root group to the list of the daemon uses.

For the stable distribution (squeeze), this problem has been fixed in version 2.1a15-1.1+squeeze1.

For the testing distribution (wheezy), this problem has been fixed in version 2.1a15-1.2.

For the unstable distribution (sid), this problem has been fixed in version 2.1a15-1.2.

We recommend that you upgrade your arpwatch packages.