HIGH · 10.0

CVE-2012-2653

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabi...

Vulnerability Description

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Lawrence Berkeley National LaboratoryArpwatch2.1a15

References

FAQ

What is CVE-2012-2653?

CVE-2012-2653 is a vulnerability with a CVSS score of 10.0 (HIGH). arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabi...

How severe is CVE-2012-2653?

CVE-2012-2653 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2653?

Check the references section above for vendor advisories and patch information. Affected products include: Lawrence Berkeley National Laboratory Arpwatch.