it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Yves-Alexis Perez <corsac AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 2481-1] arpwatch security update
- Date: Sat, 2 Jun 2012 14:50:29 +0200 (CEST)
- List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
- List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
- Old-return-path: <thijs AT kinkhorst.com>
- Priority: urgent
- Resent-date: Sat, 2 Jun 2012 12:50:47 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <ww-SPw61LhH.A.zQC.nwgyPB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2481-1 security AT debian.org
http://www.debian.org/security/ Yves-Alexis Perez
June 2, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : arpwatch
Vulnerability : fails to drop supplementary groups
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-2653
Debian Bug : 674715
Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at
least in Red Hat and Debian distributions) in order to make it drop root
privileges would fail to do so and instead add the root group to the list of
the daemon uses.
For the stable distribution (squeeze), this problem has been fixed in
version 2.1a15-1.1+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in
version 2.1a15-1.2.
For the unstable distribution (sid), this problem has been fixed in
version 2.1a15-1.2.
We recommend that you upgrade your arpwatch packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQEcBAEBAgAGBQJPygvjAAoJEOxfUAG2iX57kQMH/3fZNWPAbXpbn2EYmZsZZBqc
LVBPBL+qp++Ym/dNqm/TKop0+FSVeF3rGpTq1l9HOk6BNMm2jNZvVJ9/OF6vvIZD
zTKEDtqYNbHPMapr/zU7py5Qb/XL2prFlFjfd3A5HXCeLc1dptuhlbyUVkJYjsga
P9QJMphQ5U4CiL9EYV5xM5Co6WAlR13SFrX1cBV7il+OxpGK+lUV4NckocoQk4mG
Su3ImPyCpTbxprZH5BuPjSsGqKB6M6EKIiAA7KvTPfbNyWro53WTg7fChhEJbGzO
X4nZI1eQXJLOCDyYWZekdUFGKb4OsxQPAqRmZJnrURpxB66YWIAzyipE5UfeELI=
=nMw+
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST AT lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster AT lists.debian.org
Archive: 20120602125029.F10AC59C8C AT kinkhorst.com">http://lists.debian.org/20120602125029.F10AC59C8C AT kinkhorst.com
- [IT-SecNots] [SECURITY] [DSA 2481-1] arpwatch security update, Yves-Alexis Perez, 02.06.2012
Archiv bereitgestellt durch MHonArc 2.6.19.