CVE-2022-41318
25.12.2022, 19:15
A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.Enginsight
Vendor | Product | Version |
---|---|---|
squid-cache | squid | 2.5 ≤ 𝑥 < 5.7 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
squid |
| ||||||||||||||||||
squid3 |
|
References