Date Reported:
01 Feb 2000
Affected Packages:
apcd
Vulnerable:
Yes
For more information:
The apcd package as shipped in Debian GNU/Linux 2.1 is vulnerable to a symlink attack. If the apcd process gets a SIGUSR1 signal it will dump its status to /tmp/upsstat. However this file is not opened safely, which makes it a good target for a symlink attack.

This has been fixed in version 0.6a.nr-4slink1. We recommend you upgrade your apcd package immediately.

Fixed in:
source:
alpha:
i386:
m68k:
sparc:

apcd: symlink attack in apcd

February 1, 2000
The apcd package as shipped in Debian GNU/Linux 2.1 is vulnerable to a symlink attack

Summary

Severity

Related News