CVE-2019-18932: Race Condition
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it (after winning a /tmp/sarg/denied.intunsort race condition). The outcome will be corrupted or newly created files in privileged file system locations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18932?
CVE-2019-18932 has a high severity rating of 7 on the CVSS scale.
What type of vulnerability is CVE-2019-18932?
CVE-2019-18932 is a race condition vulnerability that allows for local privilege escalation.
How does CVE-2019-18932 affect Squid Analysis Report Generator?
CVE-2019-18932 affects Squid Analysis Report Generator by enabling an attacker to exploit a fixed temporary directory to escalate privileges.
How can I mitigate CVE-2019-18932?
Mitigation for CVE-2019-18932 involves securing the temporary directory and ensuring it is not left vulnerable to pre-creation by attackers.
In which versions of software is CVE-2019-18932 found?
CVE-2019-18932 is found in Squid Analysis Report Generator version 2.3.11 and is relevant to openSUSE Backports SLE and openSUSE Leap.