Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Ubuntu 13.04 on me high-end box - Horrible
· NVIDIA GeForce Chips Comparison Table and more
· CSF 6.09 released
· Microsoft and Google agree to build YouTube app for Windows Phone 8
· OS X 10.8.4 Build 12E55 Seeded to Developers
· Wine 1.5.31 released
· Libxvmc/Libx11 Updates for Debian
· OCZ Vertex 450 SSD Reviews and more
· Proxmox VE 3.0 released
· More Windows 8.1 features discovered in WinRT?

Upcoming News
· Appointee to the Fedora Board; election nominations closing imminently.
· Logitech k310 Washable Keyboard
· [Tech ARP] BIOS Option Of The Week - Hardware Prefetcher
· SuperTooth HD VOICE Bluetooth Speakerphone Review @ TestFreaks
· A Futurelooks News Flash - An Affordable Titan – N?= VIDIA’s GEFORCE GTX 780 Reviewed
· News: AMD's A4-5000 'Kabini' APU reviewed
· Wine release 1.5.31
· NVIDIA GeForce Chips Comparison Table @ Hardware Secrets
· Resident Evil Revelations Video Review with Kaeyi Dream @ HardwareHeaven.com
· [security-announce] openSUSE-SU-2013:0825-1: important: MozillaFirefox: update to version 21.0

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6522 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 723 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4611 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 799 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1179 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » October 2006 » USN-360-1: awstats vulnerabilities

USN-360-1: awstats vulnerabilities

Posted by Bob on: 10/10/2006 10:20 AM [ Print | 0 comment(s) ]

A new awstats vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-360-1 October 10, 2006
awstats vulnerabilities
CVE-2006-3681, CVE-2006-3682
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D

A security issue affects the following Ubuntu releases:

Ubuntu 5.04
Ubuntu 5.10
Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 5.04:
awstats 6.3-1ubuntu0.4

Ubuntu 5.10:
awstats 6.4-1ubuntu1.3

Ubuntu 6.06 LTS:
awstats 6.5-1ubuntu1.2

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

awstats did not fully sanitize input, which was passed directly to the user=
's
browser, allowing for an XSS attack. If a user was tricked into following a
specially crafted awstats URL, the user's authentication information could =
be
exposed for the domain where awstats was hosted. (CVE-2006-3681)

awstats could display its installation path under certain conditions.
However, this might only become a concern if awstats is installed into
an user's home directory. (CVE-2006-3682)


Updated packages for Ubuntu 5.04:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3-1ubun=
tu0.4.diff.gz
Size/MD5: 27234 dfd36e862db2211270ccfcda1b9f4d3a
http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3-1ubun=
tu0.4.dsc
Size/MD5: 595 967d4b14c6a5bb7e2c69c3843d15eb0a
http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3.orig.=
tar.gz
Size/MD5: 938794 edb73007530a5800d53b9f1f90c88053

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.3-1ubun=
tu0.4_all.deb
Size/MD5: 726704 52d471f9299e0bb5495c6e7db4fcc5fd

Updated packages for Ubuntu 5.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4-1ubun=
tu1.3.diff.gz
Size/MD5: 20294 23e7714e08623dd464a76b5d2618c9fa
http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4-1ubun=
tu1.3.dsc
Size/MD5: 595 e4ae507c9fc431a95b43fdc00f4a94e1
http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4.orig.=
tar.gz
Size/MD5: 918435 056e6fb0c7351b17fe5bbbe0aa1297b1

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.4-1ubun=
tu1.3_all.deb
Size/MD5: 728744 ca061e390d9ed9056bb58e14bd8bbece

Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.5-1ubun=
tu1.2.diff.gz
Size/MD5: 20075 5bdc75b3b0ae69ee240430b254b529aa
http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.5-1ubun=
tu1.2.dsc
Size/MD5: 777 67d418d1283962b1955fffe465ed5d2e
http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.5.orig.=
tar.gz
Size/MD5: 1051780 aef00b2ff5c5413bd2a868299cabd69a

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/a/awstats/awstats_6.5-1ubun=
tu1.2_all.deb
Size/MD5: 853276 6213e0f258c78ce25b73a1f7a0152f4e


--SNIs70sCzqvszXB4
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iD8DBQFFK08QDecnbV4Fd/IRApyvAKCXoxPEOTjWHzYCAkre7LsMgu4nlACgmMNY
dD0COXGFHJbs4t4T/XoBuNA=
=tN2y
-----END PGP SIGNATURE-----


Bookmark and Share

« Visiontek Radeon X1300 256MB PCI Review · Silverstone NT06 CPU Cooler Review »

Linux Compatible » News » October 2006 » USN-360-1: awstats vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition