The updated version of ntop (1.2a7-10) that was released on August 5
was found to still be insecure: It was still exploitable using buffer
overflows. Using this technique it was possible to run arbitrary code
as the user who ran ntop in web mode.
In order to permanently fix these problems an updated package has
been released that disables web mode completely. The version of
this fix is 1.2a7-11.
We recommend you upgrade or remove your ntop package immediately.