2024-10-12
ALT-BU-2024-13991-1
Branch c9f2 update bulletin.
Closed vulnerabilities
Published: 2020-12-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-29600
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891469
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891469
- https://github.com/eldy/awstats/issues/90
- https://github.com/eldy/awstats/issues/90
- [debian-lts-announce] 20201223 [SECURITY] [DLA 2506-1] awstats security update
- [debian-lts-announce] 20201223 [SECURITY] [DLA 2506-1] awstats security update
- FEDORA-2020-d1aa0e030c
- FEDORA-2020-d1aa0e030c
Published: 2020-12-12
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-35176
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References:
- https://github.com/eldy/awstats/issues/195
- https://github.com/eldy/awstats/issues/195
- [debian-lts-announce] 20201223 [SECURITY] [DLA 2506-1] awstats security update
- [debian-lts-announce] 20201223 [SECURITY] [DLA 2506-1] awstats security update
- FEDORA-2020-d1aa0e030c
- FEDORA-2020-d1aa0e030c
- FEDORA-2020-4cba5f2846
- FEDORA-2020-4cba5f2846
Published: 2022-12-04
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-46391
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Severity: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References:
- https://github.com/eldy/AWStats/pull/226
- https://github.com/eldy/AWStats/pull/226
- [debian-lts-announce] 20221205 [SECURITY] [DLA 3225-1] awstats security update
- [debian-lts-announce] 20221205 [SECURITY] [DLA 3225-1] awstats security update
- FEDORA-2023-b645c7feda
- FEDORA-2023-b645c7feda
- FEDORA-2023-fda5480804
- FEDORA-2023-fda5480804