Buffer Over-Read Vulnerability in Squid Proxy Server Software
CVE-2022-41318
8.6HIGH
What is CVE-2022-41318?
A buffer over-read vulnerability has been identified in the libntlmauth component of the Squid Proxy Server, impacting versions from 2.5 to 5.6. This issue stems from insufficient integer-overflow protection, which allows the SSPI and SMB authentication helpers to expose sensitive information by reading unintended memory locations. In certain configurations, this may result in plaintext credentials being transmitted to clients. Users are advised to upgrade to version 5.7 or later to mitigate this risk.