Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Ubuntu 20.10 USN-4953-1 Critical: AWStats Remote Code Execution Threat

ubuntu
Calendar Grey May 13, 2021
Scroller Ubuntu
Update Ubuntu to resolve problems in AWStats with risks of remote execution and unauthorized access.
Several security issues were fixed in AWStats.

Summary

Several security issues were fixed in AWStats.

Software Description:

- awstats: powerful and featureful web server log analyzer

Details:

Sean Boran discovered that AWStats incorrectly filtered certain parameters.

A remote attacker could possibly use this issue to execute arbitrary code.

(CVE-2020-29600)

It was discovered that AWStats incorrectly filtered certain parameters. A

remote attacker could possibly use this issue to access sensitive

information. (CVE-2020-35176)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
  awstats                         7.6+dfsg-2ubuntu0.20.10.1

Ubuntu 20.04 LTS:
  awstats                         7.6+dfsg-2ubuntu0.20.04.1

Ubuntu 18.04 LTS:
  awstats                         7.6+dfsg-2ubuntu0.18.04.1

Ubuntu 16.04 ESM:
  awstats                         7.4+dfsg-1ubuntu0.4+esm1

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-4953-1

  CVE-2017-1000501, CVE-2020-29600, CVE-2020-35176

Severity
critical
Lowest
Low
Medium
High
Critical

Package Information

  https://launchpad.net/ubuntu/+source/awstats/7.6+dfsg-2ubuntu0.20.10.1
  https://launchpad.net/ubuntu/+source/awstats/7.6+dfsg-2ubuntu0.20.04.1
  https://launchpad.net/ubuntu/+source/awstats/7.6+dfsg-2ubuntu0.18.04.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.