GLSA Advocate

Joined: 12 May 2004 Posts: 2663
|
Posted: Wed Jul 20, 2016 5:26 pm Post subject: [ GLSA 201607-16 ] arpwatch |
|
|
Gentoo Linux Security Advisory
Title: arpwatch: Privilege escalation (GLSA 201607-16)
Severity: high
Exploitable: local, remote
Date: July 20, 2016
Bug(s): #419375
ID: 201607-16
Synopsis
arpwatch is vulnerable to the escalation of privileges.
Background
The ethernet monitor program; for keeping track of ethernet/ip address
pairings.
Affected Packages
Package: net-analyzer/arpwatch
Vulnerable: < 2.1.15-r8
Unaffected: >= 2.1.15-r8
Architectures: All supported architectures
Description
Arpwatch does not properly drop supplementary groups.
Impact
Attackers, if able to exploit arpwatch, could escalate privileges
outside of the running process.
Workaround
There is no known workaround at this time.
Resolution
All arpwatch users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --verbose --oneshot ">=net-analyzer/arpwatch-2.1.15-r8"
|
References
CVE-2012-2653
|
|