Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 83657 - Possible critical bug in awstats 6.3-r2 leading to gaining root privileges
Summary: Possible critical bug in awstats 6.3-r2 leading to gaining root privileges
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Auditing (show other bugs)
Hardware: x86 Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://forums.gentoo.org/viewtopic-t-...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-03-01 03:25 UTC by Jakub Moc (RETIRED)
Modified: 2005-03-01 04:58 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jakub Moc (RETIRED) gentoo-dev 2005-03-01 03:25:08 UTC
Please, could someone look into this? The guys don
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2005-03-01 03:25:08 UTC
Please, could someone look into this? The guys don´t seem to be willing to file  a bug report, but this makes me really nervous. Unfortunately I cannot provide any more information on this, I just have been reading through the Gentoo Forums.

http://forums.gentoo.org/viewtopic-t-300307.html

Sorry if this is a hoax but this webapp has had a really poor security record recently. :-(

Reproducible: Always
Steps to Reproduce:
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-03-01 03:37:20 UTC
The configdir thing was fixed in 6.3-r2 (GLSA 200501-36). My guess is that the guy there either is just thinking he was rooted because the probe shows on his apache logs.

The other guy was probably running a vulnerable phpBB. I commented on the post.
Comment 3 Jakub Moc (RETIRED) gentoo-dev 2005-03-01 03:40:38 UTC
Thanks, Koon. Oh yes, phpBB is another bug-infested webapp. :-(
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-03-01 03:44:36 UTC
Hmm the guy says he was running 6.3-r2, so we better doublecheck this.
Comment 5 Tavis Ormandy (RETIRED) gentoo-dev 2005-03-01 04:16:09 UTC
I've double checked and can confirm the vulnerability that log entry was attempting to exploit is definitely fixed in 6.3-r2..the paramater is stripped of any meta characters.
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-03-01 04:58:19 UTC
OK... Someone can reopen if they can show us how the fixed awstats would be vulnerable.