arpwatch on Red Hat Linux contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered by an error in certain programs with limited operations not properly dropping group privileges when terminated. This may allow an attacker to gain escalated priviliges.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Workaround
Exploit:
Exploit Unknown
Disclosure:
Coordinated Disclosure
Solution
Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to temporarily work around the flaw by implementing the following workaround: restrict access to the arpwatch program.