~ubuntu-branches/ubuntu/warty/awstats/warty-security

  • Committer: Bazaar Package Importer
  • Author(s): Martin Pitt
  • Date: 2005-02-11 13:07:58 UTC
  • Revision ID: james.westby@ubuntu.com-20050211130758-ihj9iqvimh3alo4v
Tags: 6.0-4ubuntu0.2
* SECURITY UPDATE: fix more arbitrary command execution vulnerabilities
* wwwroot/cgi-bin/awstats.pl: remove all non-path characters from the
  "config", "logfile", "pluginmode", "loadplugin", and "noloadplugin"
  parameters (which are defined by the remote user) to prevent execution of
  arbitrary shell commands through shell metacharacters.
* References:
  similar to CAN-2005-0116
  http://packetstormsecurity.nl/0501-exploits/AWStatsVulnAnalysis.pdf
Filename Latest Rev Last Changed Committer Comment Size
..
debian 2 20 years ago Bazaar Package Importer Really fix bug#247265. Really closes: Bug#247265 ( Diff
docs 1 20 years ago Bazaar Package Importer Import upstream version 6.0 Diff
tools 1 20 years ago Bazaar Package Importer Import upstream version 6.0 Diff
wwwroot 1 20 years ago Bazaar Package Importer Import upstream version 6.0 Diff
README.TXT 1 20 years ago Bazaar Package Importer Import upstream version 6.0 6.3 KB Diff Download File