Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory [UPDATE] GLSA 200501-36:03
https://security.gentoo.org/
Severity: High
Title: AWStats: Remote code execution
Date: January 25, 2005
Updated: February 14, 2005
Bugs: #77963, #81775
ID: 200501-36:03
Update
=====
Version 6.3 of AWStats only partially fixed the input validation flaws.
Furthermore, another flaw leading to unwanted information disclosure was
found and fixed in AWStats.
The updated sections appear below.
Synopsis
=======
AWStats fails to validate certain input, which could lead to the remote
execution of arbitrary code or to the leak of information.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-www/awst...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.