arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-07-12T20:00:00

Updated: 2024-08-06T19:42:31.777Z

Reserved: 2012-05-14T00:00:00

Link: CVE-2012-2653

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-07-12T20:55:15.937

Modified: 2024-11-21T01:39:21.560

Link: CVE-2012-2653

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-05-24T00:00:00Z

Links: CVE-2012-2653 - Bugzilla