10
CVE-2012-2653
- EPSS 3.2%
- Veröffentlicht 12.07.2012 20:55:15
- Zuletzt bearbeitet 16.06.2026 23:41:48
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lawrence Berkeley National Laboratory ≫ Arpwatch Version2.1a15
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.2% | 0.865 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082553.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082565.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082569.html
http://www.debian.org/security/2012/dsa-2481
http://www.mandriva.com/security/advisories?name=MDVSA-2012:113
http://www.openwall.com/lists/oss-security/2012/05/24/12
http://www.openwall.com/lists/oss-security/2012/05/24/13
http://www.openwall.com/lists/oss-security/2012/05/24/14
http://www.openwall.com/lists/oss-security/2012/05/25/5
https://security.gentoo.org/glsa/201607-16