Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Gentoo: 200803-21 Normal: Sarg Remote Command Execution Threat

gentoo
Calendar Grey March 12, 2008
Dist Gentoo Esm H88
The recent security flaw identified in Gentoo enables unauthorized code execution through unvalidated input. Immediate upgrades advised for safeguarding.
Sarg is vulnerable to the execution of arbitrary code when processed with untrusted input files.

Summary

Gentoo Linux Security Advisory GLSA 200803-21 https://security.gentoo.org/ Severity: Normal Title: Sarg: Remote execution of arbitrary code Date: March 12, 2008 Bugs: #212208, #212731 ID: 200803-21

Synopsis ======= Sarg is vulnerable to the execution of arbitrary code when processed with untrusted input files.
Background ========= Sarg (Squid Analysis Report Generator) is a tool that provides many informations about the Squid web proxy server users activities: time, sites, traffic, etc.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/sarg < 2.2.5 >= 2.2.5
========== Sarg doesn't properly check its input for abnormal content when processing S...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here