Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Gentoo: GLSA 200508-07 High: AWStats Arbitrary Code Execution

gentoo
Calendar Grey August 20, 2005
Scroller Gentoo
Gentoo GLSA 202309-15 reports critical vulnerability in AWStats enabling remote code execution through crafted input.
AWStats fails to validate certain log input, which could lead to the execution of arbitrary Perl code during the generation of the statistics

Summary

Gentoo Linux Security Advisory GLSA 200508-07 https://security.gentoo.org/ Severity: High Title: AWStats: Arbitrary code execution using malicious Referrer information Date: August 16, 2005 Bugs: #102145 ID: 200508-07

Synopsis ======= AWStats fails to validate certain log input, which could lead to the execution of arbitrary Perl code during the generation of the statistics.
Background ========= AWStats is an advanced log file analyzer and statistics generator. In HTTP reports it parses Referrer information in order to display the most common Referrer values that caused users to visit the website.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ----------------------------------------------------------...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround