arpwatch: Privilege escalation arpwatch is vulnerable to the escalation of privileges. 2016-07-20 2016-07-20 419375 local, remote 2.1.15-r8 2.1.15-r8

The ethernet monitor program; for keeping track of ethernet/ip address pairings.

Arpwatch does not properly drop supplementary groups.

Attackers, if able to exploit arpwatch, could escalate privileges outside of the running process.

There is no known workaround at this time.

All arpwatch users should upgrade to the latest version:

# emerge --sync # emerge --ask --verbose --oneshot ">=net-analyzer/arpwatch-2.1.15-r8"
CVE-2012-2653 b-man b-man