CVE-2022-41318
25.12.2022, 19:15
A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.Enginsight
| Vendor | Product | Version |
|---|---|---|
| squid-cache | squid | 2.5 ≤ 𝑥 < 5.7 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| squid |
| ||||||||||||||||||
| squid3 |
|
References