CVE-2019-18932 describes a local privilege escalation vulnerability in Squid Analysis Report Generator (sarg) through version 2.3.11, impacting various openSUSE and sarg project distributions. The flaw stems from sarg's insecure handling of a fixed temporary directory, /tmp/sarg, which can be exploited by an attacker to pre-create the directory and place symlinks, leading to corrupted or new files in privileged locations. Rated 7.0 HIGH (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), this vulnerability requires local access and has high impact on confidentiality, integrity, and availability, but exploitation is complex due to a race condition. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.11CPE matchmatch criteria | cpe:2.3:a:squid_analysis_report_generator_project:squid_analysis_report_generator:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.