[<prev] [next>] [day] [month] [year] [list]
Message-Id: <20120602125029.F10AC59C8C@kinkhorst.com>
Date: Sat, 2 Jun 2012 14:50:29 +0200 (CEST)
From: Yves-Alexis Perez <corsac@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 2481-1] arpwatch security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2481-1 security@...ian.org
http://www.debian.org/security/ Yves-Alexis Perez
June 2, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : arpwatch
Vulnerability : fails to drop supplementary groups
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-2653
Debian Bug : 674715
Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at
least in Red Hat and Debian distributions) in order to make it drop root
privileges would fail to do so and instead add the root group to the list of
the daemon uses.
For the stable distribution (squeeze), this problem has been fixed in
version 2.1a15-1.1+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in
version 2.1a15-1.2.
For the unstable distribution (sid), this problem has been fixed in
version 2.1a15-1.2.
We recommend that you upgrade your arpwatch packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQEcBAEBAgAGBQJPygvjAAoJEOxfUAG2iX57kQMH/3fZNWPAbXpbn2EYmZsZZBqc
LVBPBL+qp++Ym/dNqm/TKop0+FSVeF3rGpTq1l9HOk6BNMm2jNZvVJ9/OF6vvIZD
zTKEDtqYNbHPMapr/zU7py5Qb/XL2prFlFjfd3A5HXCeLc1dptuhlbyUVkJYjsga
P9QJMphQ5U4CiL9EYV5xM5Co6WAlR13SFrX1cBV7il+OxpGK+lUV4NckocoQk4mG
Su3ImPyCpTbxprZH5BuPjSsGqKB6M6EKIiAA7KvTPfbNyWro53WTg7fChhEJbGzO
X4nZI1eQXJLOCDyYWZekdUFGKb4OsxQPAqRmZJnrURpxB66YWIAzyipE5UfeELI=
=nMw+
-----END PGP SIGNATURE-----
Powered by blists - more mailing lists