Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200508-07 ] AWStats: Arbitrary code execution using malicious Referrer information
Date: Tue, 16 Aug 2005 05:44:20
Message-Id: 200508160715.57134.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200508-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: AWStats: Arbitrary code execution using malicious Referrer
9 information
10 Date: August 16, 2005
11 Bugs: #102145
12 ID: 200508-07
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 AWStats fails to validate certain log input, which could lead to the
20 execution of arbitrary Perl code during the generation of the
21 statistics.
22
23 Background
24 ==========
25
26 AWStats is an advanced log file analyzer and statistics generator. In
27 HTTP reports it parses Referrer information in order to display the
28 most common Referrer values that caused users to visit the website.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 net-www/awstats < 6.5 >= 6.5
37
38 Description
39 ===========
40
41 When using a URLPlugin, AWStats fails to sanitize Referrer URL data
42 before using them in a Perl eval() routine.
43
44 Impact
45 ======
46
47 A remote attacker can include arbitrary Referrer information in a HTTP
48 request to a web server, therefore injecting tainted data in the log
49 files. When AWStats is run on this log file, this can result in the
50 execution of arbitrary Perl code with the rights of the user running
51 AWStats.
52
53 Workaround
54 ==========
55
56 Disable all URLPlugins in the AWStats configuration.
57
58 Resolution
59 ==========
60
61 All AWStats users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=net-www/awstats-6.5"
65
66 Note: Users with the vhosts USE flag set should manually use
67 webapp-config to finalize the update.
68
69 References
70 ==========
71
72 [ 1 ] CAN-2005-1527
73 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1527
74 [ 2 ] iDEFENSE Advisory
75 http://www.idefense.com/application/poi/display?id=290&type=vulnerabilities
76
77 Availability
78 ============
79
80 This GLSA and any updates to it are available for viewing at
81 the Gentoo Security Website:
82
83 http://security.gentoo.org/glsa/glsa-200508-07.xml
84
85 Concerns?
86 =========
87
88 Security is a primary focus of Gentoo Linux and ensuring the
89 confidentiality and security of our users machines is of utmost
90 importance to us. Any security concerns should be addressed to
91 security@g.o or alternatively, you may file a bug at
92 http://bugs.gentoo.org.
93
94 License
95 =======
96
97 Copyright 2005 Gentoo Foundation, Inc; referenced text
98 belongs to its owner(s).
99
100 The contents of this document are licensed under the
101 Creative Commons - Attribution / Share Alike license.
102
103 http://creativecommons.org/licenses/by-sa/2.0