ALASSQUID4-2023-001

Related Vulnerabilities: CVE-2022-41318  

A flaw was found in Squid. An incorrect integer overflow protection in the Squid SSPI and SMB authentication helpers is vulnerable to a buffer overflow attack, resulting in information disclosure or a denial of service. (CVE-2022-41318)

ALASSQUID4-2023-001


Amazon Linux 2 Security Advisory: ALASSQUID4-2023-001
Advisory Release Date: 2023-08-04 20:34 Pacific
Advisory Updated Date: 2023-09-25 22:00 Pacific
Severity: Important

Issue Overview:

A flaw was found in Squid. An incorrect integer overflow protection in the Squid SSPI and SMB authentication helpers is vulnerable to a buffer overflow attack, resulting in information disclosure or a denial of service. (CVE-2022-41318)


Affected Packages:

squid


Issue Correction:
Run yum update squid to update your system.

New Packages:
aarch64:
    squid-4.15-1.amzn2.0.4.aarch64
    squid-debuginfo-4.15-1.amzn2.0.4.aarch64

i686:
    squid-4.15-1.amzn2.0.4.i686
    squid-debuginfo-4.15-1.amzn2.0.4.i686

src:
    squid-4.15-1.amzn2.0.4.src

x86_64:
    squid-4.15-1.amzn2.0.4.x86_64
    squid-debuginfo-4.15-1.amzn2.0.4.x86_64