An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for sarg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0140-1 Rating: important References: #1156643 Cross-References: CVE-2019-18932 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sarg fixes the following issues: - CVE-2019-18932: Fixed insecure usage of /tmp/sarg which potentially allowed privilege escalation or denial of service (boo#1156643). This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-140=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): sarg-2.3.10-bp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2019-18932.html https://bugzilla.suse.com/1156643 -- . openSUSE Security Notification: Critical sarg upgrade addresses elevation of privilege vulnerability. Secure your system with the latest update.. openSUSE, Sarg Fix, Security Patch, Privilege Escalation. . Severity: Important. LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for sarg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0121-1 Rating: moderate References: #1142433 #1142435 #1142436 Cross-References: CVE-2019-1010222 CVE-2019-1010223 CVE-2019-1010224 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for aubio fixes the following issues: - CVE-2019-1010224: Fixed a denial of service caused by null pointer dereference (boo#1142435). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-121=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): aubio-debugsource-0.4.6-lp151.6.7.1 aubio-tools-0.4.6-lp151.6.7.1 aubio-tools-debuginfo-0.4.6-lp151.6.7.1 libaubio-devel-0.4.6-lp151.6.7.1 libaubio5-0.4.6-lp151.6.7.1 libaubio5-debuginfo-0.4.6-lp151.6.7.1 - openSUSE Leap 15.1 (x86_64): libaubio5-32bit-0.4.6-lp151.6.7.1 libaubio5-32bit-debuginfo-0.4.6-lp151.6.7.1 python-aubio-debugsource-0.4.6-lp151.6.7.1 python2-aubio-0.4.6-lp151.6.7.1 python2-aubio-debuginfo-0.4.6-lp151.6.7.1 python3-aubio-0.4.6-lp151.6.7.1 python3-aubio-debuginfo-0.4.6-lp151.6.7.1 References: https://www.suse.com/security/cve/CVE-2019-1010222.html https://www.suse.com/security/cve/CVE-2019-1010223.html https://www.suse.com/security/cve/CVE-2019-1010224.html https://bugzilla.suse.com/1142433 https://bugzilla.suse.com/1142435 https://bugzilla.suse.com/1142436 -- . ThisFedora update addresses several vulnerabilities and improves overall system security with a critical fix that mitigates potential exploits.. openSUSE Update, Security Patch, DoS Prevention, sarg Vulnerability. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for sarg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0117-1 Rating: important References: #1156643 Cross-References: CVE-2019-18932 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sarg fixes the following issues: - CVE-2019-18932: Fixed insecure usage of /tmp/sarg which potentially allowed privilege escalation or denial of service (boo#1156643). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-117=1 Package List: - openSUSE Leap 15.1 (x86_64): sarg-2.3.10-lp151.3.3.1 sarg-debuginfo-2.3.10-lp151.3.3.1 sarg-debugsource-2.3.10-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-18932.html https://bugzilla.suse.com/1156643 -- . This Fedora security announcement presents important information regarding a significant upgrade for apache related to a severe vulnerability.. openSUSE Security Update,sarg vulnerability,package fixes. . Severity: Important. LinuxSecurity.com Team
Multiple stack-based buffer overflow vulnerabilities were discovered in SARG allowing for remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201009-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SARG: User-assisted execution of arbitrary code Date: September 07, 2010 Bugs: #222121 ID: 201009-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple stack-based buffer overflow vulnerabilities were discovered in SARG allowing for remote code execution. Background ========= SARG is the Squid Analysis Report Generator. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/sarg < 2.2.5-r5 > = 2.2.5-r5 Description ========== Multiple vulnerabilities were discovered in SARG. For further information please consult the CVE entries referenced below. Impact ===== These vulnerabilities might allow attackers to execute arbitrary code via unknown vectors. NOTE: This is a legacy GLSA. Updates for all affected architectures are available since April 18, 2009. It is likely that your system is already no longer affected by this issue. Workaround ========= There is no known workaround at this time. Resolution ========= All SARG users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/sarg-2.2.5-r5" References ========= [ 1 ] CVE-2008-1922 https://www.cve.org/CVERecord?id=CVE-2008-1922 Availability =========== This GLSA and any updates to itare available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201009-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Sarg is vulnerable to the execution of arbitrary code when processed with untrusted input files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200803-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Sarg: Remote execution of arbitrary code Date: March 12, 2008 Bugs: #212208, #212731 ID: 200803-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Sarg is vulnerable to the execution of arbitrary code when processed with untrusted input files. Background ========= Sarg (Squid Analysis Report Generator) is a tool that provides many informations about the Squid web proxy server users activities: time, sites, traffic, etc. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/sarg < 2.2.5 > = 2.2.5 Description ========== Sarg doesn't properly check its input for abnormal content when processing Squid log files. Impact ===== A remote attacker using a vulnerable Squid as a proxy server or a reverse-proxy server can inject arbitrary content into the "User-Agent" HTTP client header, that will be processed by sarg, which will lead to the execution of arbitrary code, or JavaScript injection, allowing Cross-Site Scripting attacks and the theft of credentials. Workaround ========= There is no known workaround at this time. Resolution ========= All sarg users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/sarg-2.2.5" References ========= [ 1 ] CVE-2008-1167 https://www.cve.org/CVERecord?id=CVE-2008-1167 [ 2 ] CVE-2008-1168 https://www.cve.org/CVERecord?id=CVE-2008-1168 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200803-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.