Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/42321
http://www.securityfocus.com/bid/29141
http://www.mandriva.com/security/advisories?name=MDVSA-2009:073