PT-2012-1056 · Uc Berkeley+1 · Arpwatch+1

Kurt Seifried

·

Publicado

2012-07-12

·

Atualizado

2016-11-28

·

CVE-2012-2653

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions arpwatch versions 2.1a15
Description The issue concerns multiple vulnerabilities in the arpwatch package, which can be exploited to compromise the confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. Specifically, arpwatch does not properly drop supplementary groups, potentially allowing attackers to gain root privileges by leveraging other vulnerabilities in the daemon.
Recommendations For arpwatch version 2.1a15, consider restricting access to the daemon until a patch is available to prevent potential privilege escalation. As a temporary workaround, ensure that the daemon is run with the least privileges necessary to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03563
CVE-2012-2653
DSA-2481-1
SUSE-SU-2012_0987-1

Produtos afetados

Suse
Arpwatch