CVE-2000-0107

Linux apcd < - Local Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0107. PoCs published by anonymous.

AI-analyzed exploit summary This exploit leverages a symlink vulnerability in apcd (CVE-2000-0107) to overwrite arbitrary files, such as /.rhosts, by creating a symlink in /tmp/upsstat. When apcd receives a SIGUSR1 signal, it writes to the symlinked file, potentially allowing root access via rsh.

Description

Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · textlocallinux
https://www.exploit-db.com/exploits/19735

This exploit leverages a symlink vulnerability in apcd (CVE-2000-0107) to overwrite arbitrary files, such as /.rhosts, by creating a symlink in /tmp/upsstat. When apcd receives a SIGUSR1 signal, it writes to the symlinked file, potentially allowing root access via rsh.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: apcd (as shipped in Debian GNU/Linux 2.1)
No auth needed
Prerequisites: apcd running on the target system · ability to create symlinks in /tmp · ability to send SIGUSR1 to apcd process
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/958
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2000/20000201

Scores

EPSS 0.0079
EPSS Percentile 52.6%

Details

Status published
Products (1)
debian/debian_linux 2.1
Published Feb 01, 2000
Tracked Since Feb 18, 2026