diff options
| author | Vidar Karlsen <vidar@karlsen.tech> | 2026-03-10 17:58:29 +0000 |
|---|---|---|
| committer | Vladimir Druzenko <vvd@FreeBSD.org> | 2026-03-10 18:00:19 +0000 |
| commit | b029f6c828cd6a9c29f50a1ecfb9fef90ca409c4 (patch) | |
| tree | 4db068dcf97f03b78e9a887d6a4edcac990532f6 /databases/pgbadger/(public-mirror) | |
| parent | c2a1cd5d3c65a8e13f75d6dbcf8ded3ac7decbb6 (diff) | |
Problem:
awdownloadcsv.pl is vulnerable to command injection and path traversal,
ref [1] and [2].
The GitHub issue [1] mentions that it is deprecated, and the readme does
not list this file among the files that are (supposed to be) part of the
distribution.
Solution:
This commit prevents awdownloadcsv.pl to be installed, thus removing the
vulnerability.
[1] https://github.com/eldy/AWStats/issues/276
[2] https://www.openwall.com/lists/oss-security/2026/03/08/8
While here, clean up sorting of IPV6_RUN_DEPENDS.
PR: 293698
MFH: 2026Q1
Diffstat (limited to 'databases/pgbadger/(public-mirror)')
0 files changed, 0 insertions, 0 deletions
