~ubuntu-branches/ubuntu/dapper/awstats/dapper-updates

Viewing all changes in revision 7.

  • Committer: Bazaar Package Importer
  • Author(s): Martin Pitt
  • Date: 2006-06-07 18:40:55 UTC
  • Revision ID: james.westby@ubuntu.com-20060607184055-0bk57l947rasf3t5
Tags: 6.5-1ubuntu1.1
* SECURITY UPDATE: Arbitrary command execution as www-data.
* Add debian/patches/1003_disable_configdir.patch:
  - Disable 'configdir' CGI parameter unless AWSTATS_ENABLE_CONFIG_DIR env
    variable is set. This prevents users from putting a crafted config (with
    pipe in LogFile parameter) to e. g. /tmp and update the statistics
    through the browser.
  - Patch ported from Debian's 6.5-2.
  - CVE-2006-2644

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: