Buffer Over-Read Vulnerability in Squid Proxy Server Software
CVE-2022-41318

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
25 December 2022

What is CVE-2022-41318?

A buffer over-read vulnerability has been identified in the libntlmauth component of the Squid Proxy Server, impacting versions from 2.5 to 5.6. This issue stems from insufficient integer-overflow protection, which allows the SSPI and SMB authentication helpers to expose sensitive information by reading unintended memory locations. In certain configurations, this may result in plaintext credentials being transmitted to clients. Users are advised to upgrade to version 5.7 or later to mitigate this risk.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.