Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 16 articles for you...
203

Mageia 9 AWStats Major Command Injection Vulnerability Fix MGASA-2026-0138

MGASA-2026-0138 - Updated awstats packages fix security vulnerability. MGASA-2026-0138 - Updated awstats packages fix security vulnerability Publication date: 15 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0138.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-63261 Description: AWStats is vulnerable to Command Injection via the open function. (CVE-2025-63261) References: - https://bugs.mageia.org/show_bug.cgi?id=35407 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/GP4DGW2LGHINXKYPZWR2WJ5DMROGGO66/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-63261 SRPMS: - 9/core/awstats-7.9-1.1.mga9 . Critical update for Mageia awstats packages resolving command injection vulnerability helps secure systems.. awstats security fix, Mageia advisory MGASA-2026-0138, command injection vulnerability, Mageia package update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 15, 2026 Important Mageia
89

Fedora 44 AWStats Critical Command Injection Fix CVE-2025-63261

Fix CVE-2025-63261. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-649970e065 2026-04-25 01:21:36.172688+00:00 -------------------------------------------------------------------------------- Name : awstats Product : Fedora 44 Version : 8.0 Release : 4.fc44 URL : https://www.awstats.org/ Summary : Advanced Web Statistics Description : Advanced Web Statistics is a powerful and full-featured tool that generates advanced web server graphical statistics. This server log analyzer works from the command line or as a CGI and shows all information your log contains, in graphical web pages. It can analyze a lot of web/wap/proxy servers such as Apache, IIS, Weblogic, Webstar, Squid, ... but also mail or FTP servers. This program can measure visits, unique visitors, authenticated users, pages, domains/countries, OS busiest times, robot visits, type of files, search engines/keywords used, visit duration, HTTP errors and more... Statistics can be updated from a browser or your scheduler. The program also supports virtual servers, plugins and a lot of features. With the default configuration, the statistics are available at: http://localhost/awstats/awstats.pl -------------------------------------------------------------------------------- Update Information: Fix CVE-2025-63261 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Tim Jackson - 8.0-4 - Fix CVE-2025-63261 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449785 - CVE-2025-63261 AWStats: AWStats: Arbitrary code execution via command injection vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2449785 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-649970e065' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . CVE-2025-63261 affects awstats in Fedora 44, requiring urgent updates to prevent arbitrary code execution risks.. Fedora Update, AWStats Patch, Command Injection Issue, Web Statistics Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 25, 2026 Critical Fedora
89

Fedora 42 awstats Arbitrary Code Execution Fix CVE-2025-63261

Fix CVE-2025-63261 (rhbz #2450261). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-29b65f46e8 2026-04-20 01:04:24.758011+00:00 -------------------------------------------------------------------------------- Name : awstats Product : Fedora 42 Version : 8.0 Release : 1.fc42 URL : https://www.awstats.org/ Summary : Advanced Web Statistics Description : Advanced Web Statistics is a powerful and full-featured tool that generates advanced web server graphical statistics. This server log analyzer works from the command line or as a CGI and shows all information your log contains, in graphical web pages. It can analyze a lot of web/wap/proxy servers such as Apache, IIS, Weblogic, Webstar, Squid, ... but also mail or FTP servers. This program can measure visits, unique visitors, authenticated users, pages, domains/countries, OS busiest times, robot visits, type of files, search engines/keywords used, visit duration, HTTP errors and more... Statistics can be updated from a browser or your scheduler. The program also supports virtual servers, plugins and a lot of features. With the default configuration, the statistics are available at: http://localhost/awstats/awstats.pl -------------------------------------------------------------------------------- Update Information: Fix CVE-2025-63261 (rhbz #2450261) -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Tim Jackson - 8.0-1 - Fix CVE-2025-63261 (rhbz #2450261) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2450261 - CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2450261 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-29b65f46e8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Serious security advisory for Fedora 42 addressing arbitrary code execution in awstats. Urgent installation recommended.. Fedora 42 security advisory, awstats update, command injection fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 20, 2026 Critical Fedora
89

Fedora 43 AWStats Critical Code Exec Fix CVE-2025-63261 2026-Fad30cb6e2

Fix CVE-2025-63261 (rhbz #2450263). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fad30cb6e2 2026-04-20 00:44:47.956851+00:00 -------------------------------------------------------------------------------- Name : awstats Product : Fedora 43 Version : 8.0 Release : 2.fc43 URL : https://www.awstats.org/ Summary : Advanced Web Statistics Description : Advanced Web Statistics is a powerful and full-featured tool that generates advanced web server graphical statistics. This server log analyzer works from the command line or as a CGI and shows all information your log contains, in graphical web pages. It can analyze a lot of web/wap/proxy servers such as Apache, IIS, Weblogic, Webstar, Squid, ... but also mail or FTP servers. This program can measure visits, unique visitors, authenticated users, pages, domains/countries, OS busiest times, robot visits, type of files, search engines/keywords used, visit duration, HTTP errors and more... Statistics can be updated from a browser or your scheduler. The program also supports virtual servers, plugins and a lot of features. With the default configuration, the statistics are available at: http://localhost/awstats/awstats.pl -------------------------------------------------------------------------------- Update Information: Fix CVE-2025-63261 (rhbz #2450263) -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Tim Jackson - 8.0-2 - Fix CVE-2025-63261 (rhbz #2450263) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2450263 - CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2450263 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fad30cb6e2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical update for AWStats in Fedora 43 fixes remote code execution flaw. Ensure system security with this patch.. Fedora AWStats security update command injection CVE-2025-63261. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 20, 2026 Critical Fedora
197

Debian 11 awstats Key Command Injection Advisory DLA-4509-1 CVE-2025-63261

It was discovered that there was a potential command injection vulnerability in awstats, an analytics tool for web servers and similar services. For Debian 11 bullseye, this problem has been fixed in version 7.8-2+deb11u2.. Debian LTS Advisory DLA-4509-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb March 25, 2026 https://wiki.debian.org/LTS Package : awstats Version : 7.8-2+deb11u2 CVE ID : CVE-2025-63261 It was discovered that there was a potential command injection vulnerability in awstats, an analytics tool for web servers and similar services. For Debian 11 bullseye, this problem has been fixed in version 7.8-2+deb11u2. We recommend that you upgrade your awstats packages. For the detailed security status of awstats please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/awstats Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Discover how command injection flaws in awstats affect Debian 11 and the recommended remedy. Upgrade details included.. command injection, awstats, debian update, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 25, 2026 Important Debian LTS
172

Ubuntu: 5899-1 Moderate Security Issue: AWStats XSS Vulnerability

AWStats could allow cross-site scripting (XSS) attacks.. =========================================================================Ubuntu Security Notice USN-5899-1 February 28, 2023 awstats vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: AWStats could allow cross-site scripting (XSS) attacks. Software Description: - awstats: powerful and featureful web server log analyzer Details: It was discovered that AWStats did not properly sanitize the content of whois responses in the hostinfo plugin. An attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: awstats 7.8-2ubuntu0.22.10.1 Ubuntu 22.04 LTS: awstats 7.8-2ubuntu0.22.04.1 Ubuntu 20.04 LTS: awstats 7.6+dfsg-2ubuntu0.20.04.2 Ubuntu 18.04 LTS: awstats 7.6+dfsg-2ubuntu0.18.04.2 Ubuntu 16.04 ESM: awstats 7.4+dfsg-1ubuntu0.4+esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5899-1 CVE-2022-46391 Package Information: https://launchpad.net/ubuntu/+source/awstats/7.8-2ubuntu0.22.10.1 https://launchpad.net/ubuntu/+source/awstats/7.8-2ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/awstats/7.6+dfsg-2ubuntu0.20.04.2 https://launchpad.net/ubuntu/+source/awstats/7.6+dfsg-2ubuntu0.18.04.2 . Keep up to date on Ubuntu Security Alert USN-5900-1 concerning Joomla CSRF exploit impacting variousversions.. AWStats Security, XSS Threat, Ubuntu Update, Web Server Log Analysis. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 28, 2023 Important Ubuntu
89

Fedora 38: FEDORA-2023-c746c8gfab Urgent Awstats Cross-Site Scripting Patch

Security fix for CVE-2022-46391. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-b645c7feda 2023-01-18 01:38:16.785686 --------------------------------------------------------------------------------Name : awstats Product : Fedora 37 Version : 7.8 Release : 9.fc37 URL : https://awstats.sourceforge.io/ Summary : Advanced Web Statistics Description : Advanced Web Statistics is a powerful and full-featured tool that generates advanced web server graphical statistics. This server log analyzer works from the command line or as a CGI and shows all information your log contains, in graphical web pages. It can analyze a lot of web/wap/proxy servers such as Apache, IIS, Weblogic, Webstar, Squid, ... but also mail or FTP servers. This program can measure visits, unique visitors, authenticated users, pages, domains/countries, OS busiest times, robot visits, type of files, search engines/keywords used, visit duration, HTTP errors and more... Statistics can be updated from a browser or your scheduler. The program also supports virtual servers, plugins and a lot of features. With the default configuration, the statistics are available at: --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-46391 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 9 2023 Tim Jackson - 7.8-9 - Fix CVE-2022-46391 (rhbz #2150632) - Clean up spec file, removing conditionals for now-obsolete releases --------------------------------------------------------------------------------References: [ 1 ] Bug #2150632 - CVE-2022-46391 awstats: XSS due to improper input checks https://bugzilla.redhat.com/show_bug.cgi?id=2150632 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2023-b645c7feda' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . System enhancement for awstats in Fedora tackles CVE-2022-46391 by implementing crucial input validation upgrades.. Awstats Security Update, Fedora Security Advisory, Input Validation Improvements. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 18, 2023 Critical Fedora
89

Fedora 36 FEDORA-2023-fda5480804 Severe: Awstats XSS Issue Fix

Security fix for CVE-2022-46391. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-fda5480804 2023-01-18 01:38:39.308169 --------------------------------------------------------------------------------Name : awstats Product : Fedora 36 Version : 7.8 Release : 9.fc36 URL : Summary : Advanced Web Statistics Description : Advanced Web Statistics is a powerful and full-featured tool that generates advanced web server graphical statistics. This server log analyzer works from the command line or as a CGI and shows all information your log contains, in graphical web pages. It can analyze a lot of web/wap/proxy servers such as Apache, IIS, Weblogic, Webstar, Squid, ... but also mail or FTP servers. This program can measure visits, unique visitors, authenticated users, pages, domains/countries, OS busiest times, robot visits, type of files, search engines/keywords used, visit duration, HTTP errors and more... Statistics can be updated from a browser or your scheduler. The program also supports virtual servers, plugins and a lot of features. With the default configuration, the statistics are available at: --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-46391 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 9 2023 Tim Jackson - 7.8-9 - Fix CVE-2022-46391 (rhbz #2150632) - Clean up spec file, removing conditionals for now-obsolete releases * Wed Jul 20 2022 Fedora Release Engineering - 7.8-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon May 30 2022 Jitka Plesnikova - 7.8-7 - Perl 5.36 rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2150632 - CVE-2022-46391 awstats: XSS due to improper input checks https://bugzilla.redhat.com/show_bug.cgi?id=2150632 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-fda5480804' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . A security advisory for Fedora 36 addresses CVE-2022-46391, impacting awstats. Users must update their awstats packages to prevent potential XSS attacks and improve security. Fedora 36 Updates, Security Fix, Awstats Details, XSS Threat, CVE-2022-46391. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 18, 2023 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here