webalizer: code execution
| Package(s): | webalizer |
CVE #(s): | |
| Created: | September 10, 2014 |
Updated: | September 10, 2014 |
| Description: |
From the Red Hat bugzilla:
A stack-based buffer overflow flaw was found in the way Webalizer, a flexible web server log file analysis program, performed import of its cache from certain tab files. A remote attacker could provide a specially-crafted tab file that, when imported would lead to wcmgr executable crash or, potentially, arbitrary code execution with the privileges of the user running the wcmgr binary. |
| Alerts: |
|