Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2017-1000501

Published: 3 January 2018

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
awstats
Launchpad, Ubuntu, Debian
upstream Needs triage

precise Does not exist

trusty Does not exist
(trusty was released [7.2+dfsg-1ubuntu0.1])
xenial
Released (7.4+dfsg-1ubuntu0.2)
zesty
Released (7.6+dfsg-1ubuntu0.17.04.1)
artful
Released (7.6+dfsg-1ubuntu0.17.10.1)
Patches:
upstream: https://github.com/eldy/awstats/commit/cf219843a74c951bf5986f3a7fffa3dcf99c3899
upstream: https://github.com/eldy/awstats/commit/06c0ab29c1e5059d9e0279c6b64d573d619e1651