Bug 27920 - awstats new security issue CVE-2020-29600
Summary: awstats new security issue CVE-2020-29600
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Reported: 2020-12-24 16:31 CET by David Walser
Modified: 2021-01-14 16:14 CET (History)
4 users (show)

See Also:
Source RPM: awstats-7.7-1.mga7.src.rpm
CVE: CVE-2020-29600
Status comment:


Description David Walser 2020-12-24 16:31:22 CET
Debian-LTS has issued an advisory on December 23:

CVE-2020-35176 is for an incomplete fix for the first CVE, so we need to fix it too, but it won't be in the advsiory.

Mageia 7 is also affected.
David Walser 2020-12-24 16:31:30 CET

Whiteboard: (none) => MGA7TOO

Comment 1 David Walser 2020-12-27 22:11:26 CET
Patched packages uploaded for Mageia 7 and Cauldron.


Updated awstats package fixes security vulnerability:

It was discovered that Awstats was vulnerable to path traversal attacks. A
remote unauthenticated attacker could leverage that to perform arbitrary code
execution. The previous fix did not fully address the issue when the default
/etc/awstats/awstats.conf is not present (CVE-2020-29600).


Updated packages in core/updates_testing:

from awstats-7.7-1.1.mga7.src.rpm

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7
Assignee: bugsquad => qa-bugs
Source RPM: awstats-7.8-1.mga8.src.rpm => awstats-7.7-1.mga7.src.rpm

Comment 2 David Walser 2021-01-13 20:15:17 CET
Fedora has issued an advisory for this on January 8:
Comment 3 PC LX 2021-01-14 12:01:53 CET
Installed and tested without issue.

Tested with apache httpd daemon and existing apache logs. No issues noticed.

One thing I should mention is that there is no access restriction to the awstats.
Maybe restricting access to localhost only would be a better default, security and privacy wise.

System: Mageia 7, x86_64, Apache, Intel CPU.

$ uname -a
Linux marte 5.10.6-desktop-1.mga7 #1 SMP Sat Jan 9 20:09:55 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -q awstats
$ systemctl status httpd
● httpd.service - The Apache HTTP Server
   Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled)
   Active: active (running) since Thu 2021-01-14 10:43:40 WET; 14min ago
 Main PID: 378 (httpd)
   Status: "Total requests: 130; Idle/Busy workers 100/0;Requests/sec: 0.153; Bytes served/sec: 1.2KB/sec"
    Tasks: 66 (limit: 4695)
   Memory: 33.1M
   CGroup: /system.slice/httpd.service
           ├─378 /usr/sbin/httpd -DFOREGROUND
           ├─381 /usr/sbin/httpd -DFOREGROUND
           └─382 /usr/sbin/httpd -DFOREGROUND

jan 14 10:43:40 marte systemd[1]: Starting The Apache HTTP Server...
jan 14 10:43:40 marte systemd[1]: Started The Apache HTTP Server.

CC: (none) => mageia
Whiteboard: (none) => MGA7-64-OK

Comment 4 Thomas Andrews 2021-01-14 14:09:00 CET
Validating. Advisory in Comment 1.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 5 Aurelien Oudelet 2021-01-14 14:32:54 CET
Advisory pushed to SVN.

CC: (none) => ouaurelien
CVE: (none) => CVE-2020-29600
Keywords: (none) => advisory

Comment 6 Mageia Robot 2021-01-14 16:14:52 CET
An update for this issue has been pushed to the Mageia Updates repository.


Resolution: (none) => FIXED

Note You need to log in before you can comment on or make changes to this bug.