8.6
CVSSv3

CVE-2022-41318

Published: 25/12/2022 Updated: 08/08/2023
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A buffer over-read exists in libntlmauth in Squid 2.5 up to and including 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid

Vendor Advisories

Debian Bug report logs - #1020586 squid: CVE-2022-41318 Package: src:squid; Maintainer for src:squid is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Sep 2022 20:18:02 UTC Severity: important Tags: security, upstream Found in versions squid/56-1, squid/413- ...
Several security issues were fixed in Squid ...
Several vulnerabilities were discovered in Squid, a fully featured web proxy cache, which could result in exposure of sensitive information in the cache manager (CVE-2022-41317), or denial of service or information disclosure if Squid is configured to negotiate authentication with the SSPI and SMB authentication helpers (CVE-2022-41318) For the st ...
Synopsis Important: squid:4 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the squid:4 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update a ...
Synopsis Important: squid:4 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the squid:4 module is now available for Red Hat Enterprise Linux 81 Update Services for SAP SolutionsRed Hat Prod ...
Synopsis Important: squid security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for squid is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a secu ...
Synopsis Important: squid:4 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the squid:4 module is now available for Red Hat Enterprise Linux 82 Extended Update SupportRed Hat Product Securi ...
Synopsis Important: squid:4 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the squid:4 module is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat Product Securi ...
Synopsis Important: squid security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for squid is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a secu ...
In Squid 3x through 3528, 4x through 417, and 5x before 56, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses (CVE-2021-46784) A flaw was found in Squid An incorrect integer overflow protection in the Squid SSPI and SMB authentication helpers is vulnerable to a buffer overflow att ...
A flaw was found in Squid An incorrect integer overflow protection in the Squid SSPI and SMB authentication helpers is vulnerable to a buffer overflow attack, resulting in information disclosure or a denial of service (CVE-2022-41318) ...
In Squid 3x through 3528, 4x through 417, and 5x before 56, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses (CVE-2021-46784) A flaw was found in Squid An incorrect integer overflow protection in the Squid SSPI and SMB authentication helpers is vulnerable to a buffer overflow att ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2816 squid 56-1 57-1 Unknown Unknown wwwopenwallcom/lists/oss-security/2022/09/23/2 wwwsquid-cacheorg/Versions/v5/changesets/S ...