10

CVE-2012-2653

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.2% 0.865
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082553.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082565.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082569.html
http://www.debian.org/security/2012/dsa-2481
http://www.mandriva.com/security/advisories?name=MDVSA-2012:113
http://www.openwall.com/lists/oss-security/2012/05/24/12
http://www.openwall.com/lists/oss-security/2012/05/24/13
http://www.openwall.com/lists/oss-security/2012/05/24/14
http://www.openwall.com/lists/oss-security/2012/05/25/5
https://security.gentoo.org/glsa/201607-16