High severity7.0NVD Advisory· Published Jan 21, 2020· Updated Jun 17, 2026
CVE-2019-18932
CVE-2019-18932
Description
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it (after winning a /tmp/sarg/denied.int_unsort race condition). The outcome will be corrupted or newly created files in privileged file system locations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:a:squid_analysis_report_generator_project:squid_analysis_report_generator:*:*:*:*:*:*:*:*Range: <=2.3.11
- cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
- sarg/Squid Analysis Report Generator (sarg)description
- osv-coords2 versionspkg:rpm/opensuse/sarg&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/sarg&distro=SUSE%20Package%20Hub%2015%20SP1
< 2.3.10-lp151.3.3.1+ 1 more
- (no CPE)range: < 2.3.10-lp151.3.3.1
- (no CPE)range: < 2.3.10-bp151.4.3.1
Patches
Vulnerability mechanics
References
8- lists.opensuse.org/opensuse-security-announce/2020-01/msg00051.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00063.htmlnvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2020/01/20/6nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2020/01/27/1nvdMailing ListThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party Advisory
- seclists.org/oss-sec/2020/q1/23nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202007-32nvdThird Party Advisory
- sourceforge.net/projects/sarg/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.