• [SECURITY] [DSA 4092-1] awstats security update

    From Sebastien Delafond@1:229/2 to All on Fri Jan 19 10:20:02 2018
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4092-1 [email protected] https://www.debian.org/security/ Sebastien Delafond January 19, 2018 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : awstats
    CVE ID : CVE-2017-1000501
    Debian Bug : 885835

    The cPanel Security Team discovered that awstats, a log file analyzer,
    was vulnerable to path traversal attacks. A remote unauthenticated
    attacker could leverage that to perform arbitrary code execution.

    For the oldstable distribution (jessie), this problem has been fixed
    in version 7.2+dfsg-1+deb8u1.

    For the stable distribution (stretch), this problem has been fixed in
    version 7.6+dfsg-1+deb9u1.

    We recommend that you upgrade your awstats packages.

    For the detailed security status of awstats please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/awstats

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlphtDgACgkQEL6Jg/PV nWRmuwgAmVAKcZjARRVoHOatp4foI9QPyCtTwZAfw+46H1SoA92y72LL3lCvHfre OHoOaJdVWY937guS812xSWbfWkw+u+RCLq9WyHlrJQor1IgPnF54kNbMHnyYb5RF +63i3ZrBfqfUqBLkYhsVdDIcLRe/f973mv3MJvI8WuZyJ7c5aGx1KeL2HiWbLTeQ rf5+E6vWbAGSR13+E/5AEM1CQ69CzsTcXJo6txeQwOnVNMb3S5ln6iKHczpTcO5C FSNs7pawHGaZubFAQcf+nFjcGnA9Ix+kxWAunPtp3vXagADWfS1cnXi0QUkEG3nv d5AlDg8JvdsnTX/KudXC3nqAfEhRsw==
    =7vDn
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)