Title : Squid Analysis Report Generator User-Agent Code Execution Issues VUPEN ID : VUPEN/ADV-2008-0749 CVE ID : CVE-2008-1167
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-04
Technical Description
Multiple vulnerabilities have been identified in SARG (Squid Analysis Report Generator), which could be exploited by attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors when processing data read from the "access.log" and "useragent.log" files, which could be exploited by remote attackers to crash an affected application or execute arbitrary code by sending a malicious request with a specially crafted "User-Agent" header.