Path traversal in Debian Linux - CVE-2017-1000501

 

Path traversal in Debian Linux - CVE-2017-1000501

Published: January 3, 2018 / Updated: August 4, 2020


Vulnerability identifier: #VU33506
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000501
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.


Affected software

Debian Linux
Gentoo Linux
Arch Linux
Fedora
Ubuntu
awstats (Alpine package)
awstats (Ubuntu package)
awstats

How to mitigate CVE-2017-1000501

Install update from vendor's website.

awstats (Alpine package) - update to 7.5-r2
awstats (Ubuntu package) - addressed in versions 7.6+dfsg-2ubuntu0.18.04.1, 7.6+dfsg-2ubuntu0.20.04.1, 7.6+dfsg-2ubuntu0.20.10.1
awstats - addressed in versions 7.6-4.el7, 7.6-4.fc26, 7.6-8.fc27

External References

Related Security Bulletins