awstats: Advanced Web Statistics ---------------------------------------------------------------------- File: awstats-6.6-0.1.noarch.rpm Patchrpm: awstats-6.6-0.1.noarch.patch.rpm Version: 6.6-0.1 Size: 1114 kB Patchsize: 1073 kB Date: Fri 16 Jun 2006 16:15:59 CEST Source: awstats-6.6-0.1.src.rpm Security: Yes ---------------------------------------------------------------------- Description: This update fixes remote code execution vulnerabilities in awstats. Since backporting awstats fixes is error prone we have upgraded it to upstream version 6.6, which also includes new features. Security issues fixed: - CVE-2006-2237: missing sanitizing of the "migrate" parameter. #173041 - CVE-2006-2644: missing sanitizing of the "configdir" parameter. #173041 - Make sure open() only opens files for read/write by adding explicit < and >.