Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: 2021-0515 Security Update for arpwatch Symlink Issue

mageia
Calendar Grey November 20, 2021
Dist Mageia Esm H88
Mageia's 2021-0610 security bulletin outlines a resolution for a symbolic link vulnerability in tcptrack impacting local users.
A symbolic link (Symlink) following vulnerability in arpwatch allows local attackers with control of the runtime user to run arpwatch and to escalate to root upon the next restart ...

Summary

A symbolic link (Symlink) following vulnerability in arpwatch allows local attackers with control of the runtime user to run arpwatch and to escalate to root upon the next restart of arpwatch. (CVE-2021-25321)

References

- https://bugs.mageia.org/show_bug.cgi?id=29188

- https://lists.suse.com/pipermail/sle-security-updates/2021-June/009098.html

-

- https://www.cve.org/CVERecord?id=CVE-2021-25321

Resolution

SRPMS

- 8/core/arpwatch-2.1a15-21.2.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 20 Nov 2021
URL: https://advisories.mageia.org/MGASA-2021-0515.html
Type: security
CVE: CVE-2021-25321

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here