Input validation error in arpwatch - CVE-2012-2653

 

Input validation error in arpwatch - CVE-2012-2653

Published: July 12, 2012 / Updated: August 4, 2020


Vulnerability identifier: #VU33951
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2653
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.


Affected software

arpwatch
Gentoo Linux
arpwatch (Alpine package)
bind (Alpine package)

How to mitigate CVE-2012-2653

Install update from vendor's website.

arpwatch (Alpine package) - update to 2.1a15-r4
bind (Alpine package) - update to 9.7.6_p1-r0

External References

Related Security Bulletins