I was doing some research on this and I found that as long as your awstat.pl is protected by htaccess you are fine. If you have it publicly viewable, well then you're in trouble. If you reach it like this:
http://domain.com/cgi-bin/awstats/awstats.pl -that's bad. If it can only be accessed via CPanel, which is a protected area, you should be fine without the update.
Do people really install Awstats in public directories? Why?