CVE-2008-1922
published 2008-05-13CVE-2008-1922: Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.
PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.78%
88.7th percentile
Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sarg | < sarg 2.2.4-1 (bookworm) | sarg 2.2.4-1 (bookworm) |
| pedro_lineu_orso | sarg | >= 0 < 2.2.4-1 | 2.2.4-1 |
| pedro_lineu_orso | sarg | >= 0 < 2.2.4-1 | 2.2.4-1 |
| pedro_lineu_orso | sarg | >= 0 < 2.2.4-1 | 2.2.4-1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m2m9-74wm-9cc3: Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file
ghsa_unreviewed·2022-05-01
CVE-2008-1922 [HIGH] CWE-119 GHSA-m2m9-74wm-9cc3: Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file
Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.
OSV
CVE-2008-1922: Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file
osv·2008-05-13·CVSS 10.0
CVE-2008-1922 [CRITICAL] CVE-2008-1922: Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file
Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.
Red Hat
kvm: qemu-nbd block format auto-detection vulnerability
vendor_redhat·2013-04-15·CVSS 4.9
CVE-2013-1922 [MEDIUM] kvm: qemu-nbd block format auto-detection vulnerability
kvm: qemu-nbd block format auto-detection vulnerability
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
Statement: Not vulnerable.
This issue does not affect versions of kvm and xen packages as shipped with Red Hat Enterprise Linux 5. This issue does not affect versions of qemu-kvm packages as shipped with Red Hat Enterprise Linux 5 and 6.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2008-1922: sarg - Multiple stack-based buffer overflows in Sarg might allow attackers to execute a...
vendor_debian·2008·CVSS 10.0
CVE-2008-1922 [CRITICAL] CVE-2008-1922: sarg - Multiple stack-based buffer overflows in Sarg might allow attackers to execute a...
Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.
Scope: local
bookworm: resolved (fixed in 2.2.4-1)
forky: resolved (fixed in 2.2.4-1)
sid: resolved (fixed in 2.2.4-1)
trixie: resolved (fixed in 2.2.4-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.htmlhttp://secunia.com/advisories/30156http://secunia.com/advisories/30202http://www.mandriva.com/security/advisories?name=MDVSA-2009:073http://www.securityfocus.com/bid/29141https://exchange.xforce.ibmcloud.com/vulnerabilities/42321http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.htmlhttp://secunia.com/advisories/30156http://secunia.com/advisories/30202http://www.mandriva.com/security/advisories?name=MDVSA-2009:073http://www.securityfocus.com/bid/29141https://exchange.xforce.ibmcloud.com/vulnerabilities/42321
2008-05-13
Published