Path traversal in Debian Linux - CVE-2017-1000501
Published: January 3, 2018 / Updated: August 4, 2020
Vulnerability identifier: #VU33506
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000501
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
Affected software
Debian Linux
Gentoo Linux
Arch Linux
Fedora
Ubuntu
awstats (Alpine package)
awstats (Ubuntu package)
awstats
Gentoo Linux
Arch Linux
Fedora
Ubuntu
awstats (Alpine package)
awstats (Ubuntu package)
awstats
How to mitigate CVE-2017-1000501
Install update from vendor's website.
awstats (Alpine package) - update to 7.5-r2
awstats (Ubuntu package) - addressed in versions 7.6+dfsg-2ubuntu0.18.04.1, 7.6+dfsg-2ubuntu0.20.04.1, 7.6+dfsg-2ubuntu0.20.10.1
awstats - addressed in versions 7.6-4.el7, 7.6-4.fc26, 7.6-8.fc27
awstats (Ubuntu package) - addressed in versions 7.6+dfsg-2ubuntu0.18.04.1, 7.6+dfsg-2ubuntu0.20.04.1, 7.6+dfsg-2ubuntu0.20.10.1
awstats - addressed in versions 7.6-4.el7, 7.6-4.fc26, 7.6-8.fc27
External References
- http://www.awstats.org/
- https://github.com/eldy/awstats/commit/06c0ab29c1e5059d9e0279c6b64d573d619e1651
- https://github.com/eldy/awstats/commit/cf219843a74c951bf5986f3a7fffa3dcf99c3899
- https://lists.debian.org/debian-lts-announce/2018/01/msg00012.html
- https://security.gentoo.org/glsa/202007-37
- https://www.debian.org/security/2018/dsa-4092