CVE-2022-41318: Integer Overflow
A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-41318.
What is the severity of CVE-2022-41318?
The severity of CVE-2022-41318 is high, with a severity value of 8.6.
Which software is affected by CVE-2022-41318?
Squid versions 2.5 through 5.6 are affected by CVE-2022-41318.
What is the impact of CVE-2022-41318?
Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers in Squid are vulnerable to reading unintended memory locations, potentially exposing cleartext credentials.
Are there any patches or advisories available for CVE-2022-41318?
Yes, patches and advisories are available. You can find them at the following links: [link1](http://www.squid-cache.org/Versions/v4/changesets/SQUID-2022_2.patch), [link2](http://www.squid-cache.org/Versions/v5/changesets/SQUID-2022_2.patch), [link3](https://github.com/squid-cache/squid/security/advisories/GHSA-394c-rr7q-6g78)