Debian DSA-2481-1 : arpwatch - fails to drop supplementary groups
Critical Nessus Plugin ID 59759
The remote Debian host is missing a security-related update.
Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at least in Red Hat and Debian distributions) in order to make it drop root privileges would fail to do so and instead add the root group to the list of the daemon uses.
Upgrade the arpwatch packages. For the stable distribution (squeeze), this problem has been fixed in version 2.1a15-1.1+squeeze1.