VYPR

rpm package

opensuse/sarg&distro=openSUSE Leap 15.1

pkg:rpm/opensuse/sarg&distro=openSUSE%20Leap%2015.1

Vulnerabilities (1)

  • CVE-2019-18932Jan 21, 2020
    affected < 2.3.10-lp151.3.3.1fixed 2.3.10-lp151.3.3.1

    log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create t