Summary
The remote host is missing an update to arpwatch
announced via advisory DSA 2481-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202481-1
Insight
Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at least in Red Hat and Debian distributions) in order to make it drop root privileges would fail to do so and instead add the root group to the list of the daemon uses.
For the stable distribution (squeeze), this problem has been fixed in version 2.1a15-1.1+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in version 2.1a15-1.2.
For the unstable distribution (sid), this problem has been fixed in version 2.1a15-1.2.
We recommend that you upgrade your arpwatch packages.
Severity
Classification
-
CVE CVE-2012-2653 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities