2 Jun 2012 14:50
[DSA 2481-1] arpwatch security update
Yves-Alexis Perez <corsac <at> debian.org>
2012-06-02 12:50:29 GMT
2012-06-02 12:50:29 GMT
------------------------------------------------------------------------- Debian Security Advisory DSA-2481-1 security <at> debian.org http://www.debian.org/security/ Yves-Alexis Perez June 2, 2012 http://www.debian.org/security/faq ------------------------------------------------------------------------- Package : arpwatch Vulnerability : fails to drop supplementary groups Problem type : remote Debian-specific: no CVE ID : CVE-2012-2653 Debian Bug : 674715 Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at least in Red Hat and Debian distributions) in order to make it drop root privileges would fail to do so and instead add the root group to the list of the daemon uses. For the stable distribution (squeeze), this problem has been fixed in version 2.1a15-1.1+squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 2.1a15-1.2. For the unstable distribution (sid), this problem has been fixed in version 2.1a15-1.2. We recommend that you upgrade your arpwatch packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce <at> lists.debian.org
RSS Feed