[ GLSA 200501-36 ] AWStats: Remote code execution

From: Luke Macken (lewk_at_gentoo.org)
Date: 01/25/05

  • Next message: Miroslav Kubik: "wifi AP + broadcoast ping"
    Date: Tue, 25 Jan 2005 15:13:13 -0500
    To: gentoo-announce@gentoo.org
    
    
    

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 200501-36
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

      Severity: High
         Title: AWStats: Remote code execution
          Date: January 25, 2005
          Bugs: #77963
            ID: 200501-36

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    AWStats fails to validate certain input, which could lead to the remote
    execution of arbitrary code.

    Background
    ==========

    AWStats is an advanced log file analyzer and statistics generator.

    Affected packages
    =================

        -------------------------------------------------------------------
         Package / Vulnerable / Unaffected
        -------------------------------------------------------------------
      1 net-www/awstats < 6.3 >= 6.3

    Description
    ===========

    When 'awstats.pl' is run as a CGI script, it fails to validate specific
    inputs which are used in a Perl open() function call.

    Impact
    ======

    A remote attacker could supply AWStats malicious input, potentially
    allowing the execution of arbitrary code with the rights of the web
    server.

    Workaround
    ==========

    Making sure that AWStats does not run as a CGI script will avoid the
    issue, but we recommend that users upgrade to the latest version, which
    fixes these bugs.

    Resolution
    ==========

    All AWStats users should upgrade to the latest version:

        # emerge --sync
        # emerge --ask --oneshot --verbose ">=net-www/awstats-6.3"

    References
    ==========

      [ 1 ] AWStats ChangeLog
            http://awstats.sourceforge.net/docs/awstats_changelog.txt
      [ 2 ] iDEFENSE Advisory
            http://www.idefense.com/application/poi/display?id=185

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

      http://security.gentoo.org/glsa/glsa-200501-36.xml

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    http://bugs.gentoo.org.

    License
    =======

    Copyright 2005 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    http://creativecommons.org/licenses/by-sa/2.0

    
    



  • Next message: Miroslav Kubik: "wifi AP + broadcoast ping"

    Relevant Pages

    • [ GLSA 200501-36 ] AWStats: Remote code execution
      ... AWStats is an advanced log file analyzer and statistics generator. ... allowing the execution of arbitrary code with the rights of the web ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)
    • UPDATE: [ GLSA 200501-36 ] AWStats: Remote code execution
      ... Version 6.3 of AWStats only partially fixed the input validation flaws. ... another flaw leading to unwanted information disclosure was ... AWStats fails to validate certain input, which could lead to the remote ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Bugtraq)
    • [Full-Disclosure] [gentoo-announce] UPDATE: [ GLSA 200501-36 ] AWStats: Remote code execution
      ... Version 6.3 of AWStats only partially fixed the input validation flaws. ... another flaw leading to unwanted information disclosure was ... AWStats fails to validate certain input, which could lead to the remote ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)
    • [Full-Disclosure] UPDATE: [ GLSA 200501-36 ] AWStats: Remote code execution
      ... Version 6.3 of AWStats only partially fixed the input validation flaws. ... another flaw leading to unwanted information disclosure was ... AWStats fails to validate certain input, which could lead to the remote ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)
    • UPDATE: [ GLSA 200501-36 ] AWStats: Remote code execution
      ... Version 6.3 of AWStats only partially fixed the input validation flaws. ... another flaw leading to unwanted information disclosure was ... AWStats fails to validate certain input, which could lead to the remote ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)