First published: Fri Dec 11 2020(Updated: )
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Awstats Awstats | <=7.8 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35176 is a vulnerability in AWStats through 7.8 that allows a partial absolute pathname to be accepted, potentially exposing sensitive information.
The severity of CVE-2020-35176 is medium with a CVSS score of 5.3.
CVE-2020-35176 affects AWStats through version 7.8 by allowing a partial absolute pathname to be accepted, which was not intended.
CVE-2020-35176 impacts Debian Debian Linux 9.0 as it is one of the affected software versions.
Yes, the fix for CVE-2020-35176 has been released. It is recommended to update to the latest version of AWStats.