VDB
CVE-2008-1167
CVE-2008-1167
PUBLISHED
CVSS 10 CRITICAL
Stack-based buffer overflow in the useragent function in useragent.c in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to execute arbitrary code via a long Squid proxy server User-Agent header. NOTE: some of these details are obtained from third party information.
EPSS 13.05% · 94.2th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
13.05%
94.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| sarg | squid_analysis_report_generator | 2.2.3.1 |
Timeline
- Mar 5, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- sarg-useragent-bo(40970) vdb
- http://sourceforge.net/project/shownotes.php?release_id=581212 url
- ADV-2008-0749 vdb
- 28668 third-party-advisory
- GLSA-200803-21 vendor-advisory
- MDVSA-2008:079 vendor-advisory
- 29309 third-party-advisory
- 1019536 vdb
- SUSE-SR:2008:006 vendor-advisory
- 29323 third-party-advisory
- 20080302 Squid Analysis Report Generator <= 2.2.3.1 buffer overflow mailing-list
- 29500 third-party-advisory
- 28077 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-1167 advisory