This service will be undergoing maintenance at 00:00 UTC, 2016-09-28. It is expected to last about 1 hours

Bug 871159 (CVE-2012-4547)

Summary: CVE-2012-4547 awstats: potentially susceptible to XSS attacks
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aurelien, plautrba, redhatbugs, rpm
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20110924,reported=20121025,source=oss-security,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:P/A:N,fedora-all/awstats=affected,epel-all/awstats=affected,cwe=CWE-79[auto]
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-07-24 13:15:29 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On: 871189, 871190    
Bug Blocks:    

Description Vincent Danen 2012-10-29 15:00:35 EDT
A new CleanXSS() function was added [1] to awstats' awredir.pl cgi script and is part of the 7.1 release [2].  The additional function aims to clean strings of HTML tags so as to avoid XSS flaws.

It doesn't indicate whether or not it was possible to actually inject arbitrary HTML into these strings or whether this was just a hardening mechanism, however this would be applicable to all currently supported versions of awstats.

[1] http://awstats.cvs.sourceforge.net/viewvc/awstats/awstats/wwwroot/cgi-bin/awredir.pl?r1=1.13&r2=1.14
[2] http://awstats.sourceforge.net/docs/awstats_changelog.txt
Comment 1 Vincent Danen 2012-10-29 17:02:12 EDT
Created awstats tracking bugs for this issue

Affects: fedora-all [bug 871189]
Affects: epel-all [bug 871190]
Comment 2 Fedora Update System 2012-11-23 02:37:31 EST
awstats-7.0-11.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 3 Fedora Update System 2012-11-28 06:37:07 EST
awstats-7.0-9.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2013-05-17 18:19:13 EDT
awstats-7.0-3.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 5 Zenon Panoussis 2013-05-23 13:06:58 EDT
The awstats-7.0-3.el6 package changes the location of files and directory structure compared to the previous release (awstats-7.0-2.el6). As a result, updating breaks all configurations.
Comment 6 Petr Lautrbach 2013-05-24 04:29:31 EDT
(In reply to Zenon Panoussis from comment #5)
> The awstats-7.0-3.el6 package changes the location of files and directory
> structure compared to the previous release (awstats-7.0-2.el6). As a result,
> updating breaks all configurations.

There was no change between awstats-7.0-2.el6 and awstats-7.0-3.el6 related to the locations. But if you have any issue, please file a new bug please.