SHARE
Facebook X Pinterest WhatsApp

[Debian] Security Advisory: New version of apcd released

Written By
thumbnail
Web Webster
Web Webster
Feb 3, 2000

Date: Wed, 2 Feb 2000 10:12:51 -0800
From: Aleph One
To: BUGTRAQ@SECURITYFOCUS.COM
Reply to: Aleph One

- ------------------------------------------------------------------------
Debian Security Advisory                             security@debian.org
http://www.debian.org/security/                      Wichert Akkerman
February  1, 2000
- ------------------------------------------------------------------------

Package: apcd
Vulnerability type: symlink attack
Debian-specific: no

The apcd package as shipped in Debian GNU/Linux 2.1 is
vulnerable to a symlink attack. If the apcd process gets a SIGUSR1
signal it will dump its status to /tmp/upsstat. However this file
is not opened safely, which makes it a good target for a symlink
attack.

This has been fixed in version 0.6a.nr-4slink1. We recommend you
upgrade your apcd package immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

Debian GNU/Linux 2.1 alias slink
– ——————————–

This version of Debian was released only for Intel ia32, the
Motorola 680×0, the alpha and the Sun sparc architecture.

Source archives:
http://security.debian.org/dists/stable/updates/source/apcd_0.6a.nr-4slink1.diff.gz
MD5 checksum: 418d34e54e080c2129b8a686e8423d6d
http://security.debian.org/dists/stable/updates/source/apcd_0.6a.nr-4slink1.dsc
MD5 checksum: f9be18f528e8a067696673337e1198ca
http://security.debian.org/dists/stable/updates/source/apcd_0.6a.nr.orig.tar.gz
MD5 checksum: 4a714a8de33cc482b678c0d21b26d76e

Alpha architecture:
http://security.debian.org/dists/stable/updates/binary-alpha/apcd_0.6a.nr-4slink1_alpha.deb
MD5 checksum: 00210d5c30732f2bbaf68291f2d7e8d8

Intel ia32 architecture:
http://security.debian.org/dists/stable/updates/binary-i386/apcd_0.6a.nr-4slink1_i386.deb
MD5 checksum: cff51852635922507c37f96df99d8e76

Motorola 680x0 architecture:
http://security.debian.org/dists/stable/updates/binary-m68k/apcd_0.6a.nr-4slink1_m68k.deb
MD5 checksum: 827079cf5f0819653635873ded1f4a75

Sun Sparc architecture:
http://security.debian.org/dists/stable/updates/binary-sparc/apcd_0.6a.nr-4slink1_sparc.deb
MD5 checksum: d56b7b9ea14c4af81856dd3e1b480e92

These files will be moved into
ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/
soon.

For not yet released architectures please refer to the
appropriate directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/
.


—————————————————————————-

For apt-get: deb http://security.debian.org/
stable updates
For dpkg-ftp: ftp://security.debian.org/debian-security
dists/stable/updates

Mailing list: debian-security-announce@lists.debian.org

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

A Thorough Approach to Improve the Privacy and Security of Your Linux PC
Damien
Oct 24, 2024
Several Russian Maintainers Removed From Linux Kernel Due To Compliance Concerns
Senthil Kumar
Oct 23, 2024
OpenSSH Splits Again: New Authentication Binary Unveiled
Bobby Borisov
Oct 16, 2024
13 Best Free and Open Source Anti-Malware Tools
webmaster
Oct 14, 2024
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.