Bug 871159 (CVE-2012-4547) - CVE-2012-4547 awstats: potentially susceptible to XSS attacks
Summary: CVE-2012-4547 awstats: potentially susceptible to XSS attacks
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-4547
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 871189 871190
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-10-29 19:00 UTC by Vincent Danen
Modified: 2019-09-29 12:56 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-07-24 17:15:29 UTC
Embargoed:


Attachments (Terms of Use)

Description Vincent Danen 2012-10-29 19:00:35 UTC
A new CleanXSS() function was added [1] to awstats' awredir.pl cgi script and is part of the 7.1 release [2].  The additional function aims to clean strings of HTML tags so as to avoid XSS flaws.

It doesn't indicate whether or not it was possible to actually inject arbitrary HTML into these strings or whether this was just a hardening mechanism, however this would be applicable to all currently supported versions of awstats.

[1] http://awstats.cvs.sourceforge.net/viewvc/awstats/awstats/wwwroot/cgi-bin/awredir.pl?r1=1.13&r2=1.14
[2] http://awstats.sourceforge.net/docs/awstats_changelog.txt

Comment 1 Vincent Danen 2012-10-29 21:02:12 UTC
Created awstats tracking bugs for this issue

Affects: fedora-all [bug 871189]
Affects: epel-all [bug 871190]

Comment 2 Fedora Update System 2012-11-23 07:37:31 UTC
awstats-7.0-11.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 3 Fedora Update System 2012-11-28 11:37:07 UTC
awstats-7.0-9.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2013-05-17 22:19:13 UTC
awstats-7.0-3.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Zenon Panoussis 2013-05-23 17:06:58 UTC
The awstats-7.0-3.el6 package changes the location of files and directory structure compared to the previous release (awstats-7.0-2.el6). As a result, updating breaks all configurations.

Comment 6 Petr Lautrbach 2013-05-24 08:29:31 UTC
(In reply to Zenon Panoussis from comment #5)
> The awstats-7.0-3.el6 package changes the location of files and directory
> structure compared to the previous release (awstats-7.0-2.el6). As a result,
> updating breaks all configurations.

There was no change between awstats-7.0-2.el6 and awstats-7.0-3.el6 related to the locations. But if you have any issue, please file a new bug please.


Note You need to log in before you can comment on or make changes to this bug.