The apcd package as shipped in Debian GNU/Linux 2.1 is vulnerable to a symlink attack. If the apcd process gets a SIGUSR1 signal it will dump its status to /tmp/upsstat. However this file is not opened safely, which makes it a good target for a symlink attack. This has been fixed in version 0.6a.nr-4slink1. We recommend you upgrade your apcd package immediately.. Date Reported: 01 Feb 2000 Affected Packages: apcd Vulnerable: Yes For more information: The apcd package as shipped in Debian GNU/Linux 2.1 is vulnerable to a symlink attack. If the apcd process gets a SIGUSR1 signal it will dump its status to /tmp/upsstat. However this file is not opened safely, which makes it a good target for a symlink attack. This has been fixed in version 0.6a.nr-4slink1. We recommend you upgrade your apcd package immediately. Fixed in: source: alpha: i386: m68k: sparc: . Debian GNU/Linux urgently addresses a critical symlink attack vulnerability in apcd. Immediate upgrade recommended.. Debian Security, apcd Upgrade, Symlink Attack Response. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.