Alerts This Week
Warning Icon 1 1,154
Alerts This Week
Warning Icon 1 1,154

Ubuntu 20.10 USN-4953-1 Critical: AWStats Remote Code Execution Threat

ubuntu
Calendar Grey May 13, 2021
Dist Ubuntu Esm H88
Update Ubuntu to resolve problems in AWStats with risks of remote execution and unauthorized access.
Several security issues were fixed in AWStats.

Summary

Several security issues were fixed in AWStats.

Software Description:

- awstats: powerful and featureful web server log analyzer

Details:

Sean Boran discovered that AWStats incorrectly filtered certain parameters.

A remote attacker could possibly use this issue to execute arbitrary code.

(CVE-2020-29600)

It was discovered that AWStats incorrectly filtered certain parameters. A

remote attacker could possibly use this issue to access sensitive

information. (CVE-2020-35176)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
  awstats                         7.6+dfsg-2ubuntu0.20.10.1

Ubuntu 20.04 LTS:
  awstats                         7.6+dfsg-2ubuntu0.20.04.1

Ubuntu 18.04 LTS:
  awstats                         7.6+dfsg-2ubuntu0.18.04.1

Ubuntu 16.04 ESM:
  awstats                         7.4+dfsg-1ubuntu0.4+esm1

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-4953-1

  CVE-2017-1000501, CVE-2020-29600, CVE-2020-35176

Severity
critical
Lowest
Low
Medium
High
Critical

Package Information

  https://launchpad.net/ubuntu/+source/awstats/7.6+dfsg-2ubuntu0.20.10.1
  https://launchpad.net/ubuntu/+source/awstats/7.6+dfsg-2ubuntu0.20.04.1
  https://launchpad.net/ubuntu/+source/awstats/7.6+dfsg-2ubuntu0.18.04.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here