Bug 871159 - (CVE-2012-4547) CVE-2012-4547 awstats: potentially susceptible to XSS attacks
CVE-2012-4547 awstats: potentially susceptible to XSS attacks
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20110924,repor...
: Security
Depends On: 871189 871190
Blocks:
  Show dependency treegraph
 
Reported: 2012-10-29 15:00 EDT by Vincent Danen
Modified: 2016-03-04 07:52 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-07-24 13:15:29 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2012-10-29 15:00:35 EDT
A new CleanXSS() function was added [1] to awstats' awredir.pl cgi script and is part of the 7.1 release [2].  The additional function aims to clean strings of HTML tags so as to avoid XSS flaws.

It doesn't indicate whether or not it was possible to actually inject arbitrary HTML into these strings or whether this was just a hardening mechanism, however this would be applicable to all currently supported versions of awstats.

[1] http://awstats.cvs.sourceforge.net/viewvc/awstats/awstats/wwwroot/cgi-bin/awredir.pl?r1=1.13&r2=1.14
[2] http://awstats.sourceforge.net/docs/awstats_changelog.txt
Comment 1 Vincent Danen 2012-10-29 17:02:12 EDT
Created awstats tracking bugs for this issue

Affects: fedora-all [bug 871189]
Affects: epel-all [bug 871190]
Comment 2 Fedora Update System 2012-11-23 02:37:31 EST
awstats-7.0-11.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 3 Fedora Update System 2012-11-28 06:37:07 EST
awstats-7.0-9.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2013-05-17 18:19:13 EDT
awstats-7.0-3.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 5 Zenon Panoussis 2013-05-23 13:06:58 EDT
The awstats-7.0-3.el6 package changes the location of files and directory structure compared to the previous release (awstats-7.0-2.el6). As a result, updating breaks all configurations.
Comment 6 Petr Lautrbach 2013-05-24 04:29:31 EDT
(In reply to Zenon Panoussis from comment #5)
> The awstats-7.0-3.el6 package changes the location of files and directory
> structure compared to the previous release (awstats-7.0-2.el6). As a result,
> updating breaks all configurations.

There was no change between awstats-7.0-2.el6 and awstats-7.0-3.el6 related to the locations. But if you have any issue, please file a new bug please.

Note You need to log in before you can comment on or make changes to this bug.