security advisorydebianimportant
It was discovered that there was a potential command injection vulnerability in awstats, an analytics tool for web servers and similar services. For Debian 11 bullseye, this problem has been fixed in version 7.8-2+deb11u2.. Debian LTS Advisory DLA-4509-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb March 25, 2026 https://wiki.debian.org/LTS Package : awstats Version : 7.8-2+deb11u2 CVE ID : CVE-2025-63261 It was discovered that there was a potential command injection vulnerability in awstats, an analytics tool for web servers and similar services. For Debian 11 bullseye, this problem has been fixed in version 7.8-2+deb11u2. We recommend that you upgrade your awstats packages. For the detailed security status of awstats please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/awstats Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Discover how command injection flaws in awstats affect Debian 11 and the recommended remedy. Upgrade details included.. command injection, awstats, debian update, security patch. . Severity: Important. LinuxSecurity.com Team
Mar 25, 2026
•Important
Debian LTS