Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Gentoo: GLSA 200606-06 High: AWStats Remote Code Execution Threat

gentoo
Calendar Grey June 7, 2006
Scroller Gentoo
Gentoo Linux Security Alert GLSA 202309-15 detailing critical vulnerabilities in OpenSSL permitting unauthorized access to sensitive data.
AWStats contains a bug in the sanitization of the input parameters which can lead to the remote execution of arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200606-06 https://security.gentoo.org/ Severity: High Title: AWStats: Remote execution of arbitrary code Date: June 07, 2006 Bugs: #130487 ID: 200606-06

Synopsis ======= AWStats contains a bug in the sanitization of the input parameterswhich can lead to the remote execution of arbitrary code.
Background ========= AWStats is an advanced log file analyzer and statistics generator.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-www/awstats < 6.5-r1 >= 6.5-r1
========== Hendrik Weimer has found that if updating the statistics via the web frontend is enabled, it is possible to inject arbitrary code via a pipe character...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround