Description of Problem: The droproot patches for tcpdump and arpwatch don't have a setgroups(0, NULL) call so arpwatch and tcpdump keep (root's) supplemental groups. Updated patches are in: http://www.uku.fi/~jhuuskon/ Or just add setgroups(0, NULL) call before setgid().
will be fixed in tcpdump--3.6.2-4