Advanced Web Statistics (awstat) upstream has released new (6.95) version, addressing two security related issues. Quoting from awstats Changelog: - Fix security in awredir.pl script by adding a security key required by default. - Enhance security of parameter sanitizing function. CVE Request: ------------ http://www.openwall.com/lists/oss-security/2009/11/22/1
These issues affect the versions of the awstats package, as shipped with Fedora releases of 10, 11, 12 and probably also as shipped with Extra Packages for Enterprise Linux 5 (EPEL-5) project. Please upgrade to new version.
awstats-6.95-1.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/awstats-6.95-1.fc12
awstats-6.95-1.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.