Sarg: Local privilege escalation — GLSA 202007-32

A flaw in Sarg may allow local privilege escalation.

Affected packages

net-analyzer/sarg on all architectures
Affected versions < 2.4.0
Unaffected versions >= 2.4.0

Background

Sarg (Squid Analysis Report Generator) is a tool that provides many informations about the Squid web proxy server users activities: time, sites, traffic, etc.

Description

A flaw in Sarg’s handling of temporary directories was discovered.

Impact

A local attacker may be able to escalate privileges.

Workaround

There is no known workaround at this time.

Resolution

All Sarg users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-analyzer/sarg-2.4.0"
 

References

Release date
July 27, 2020

Latest revision
July 27, 2020: 1

Severity
high

Exploitable
local

Bugzilla entries