Security Breach ?

Thomas Cameron thomas.cameron at camerontech.com
Thu Mar 3 05:09:22 UTC 2005


On Wed, 2005-03-02 at 22:53 -0500, Chris Strzelczyk wrote:
> On Mar 2, 2005, at 10:37 PM, Matt Florido wrote:
> 
> > Are you running any other perl applications that you are aware of?  
> > Out of curiosity, are you running a website statistical gathering tool 
> > called awstats?
> 
> Yes I am running awstats 6.1.  I was just looking into this application 
> as I forgot to list it in
> my previous emails.  I am two versions back with some security holes 
> listed.  This is somewhat of
> a learning experience and I will make sure I am never behind in these 
> small programs again.
> 
> =cs

I just had a client's server owned because of awstats.  There was a
security release on 24 February.

Thomas




More information about the fedora-list mailing list