Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-41318

Опубликовано: 25 дек. 2022
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
Версия от 2.5 (включая) до 5.7 (исключая)

EPSS

Процентиль: 29%
0.001
Низкий

8.6 High

CVSS3

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 2 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

CVSS3: 8.6
redhat
больше 2 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

CVSS3: 8.6
debian
больше 2 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through ...

CVSS3: 7.5
redos
больше 2 лет назад

Уязвимость Squid

rocky
больше 2 лет назад

Important: squid:4 security update

EPSS

Процентиль: 29%
0.001
Низкий

8.6 High

CVSS3

Дефекты

CWE-190
CWE-190