Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-41318

Опубликовано: 25 дек. 2022
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
Версия от 2.5 (включая) до 5.7 (исключая)

EPSS

Процентиль: 37%
0.00157
Низкий

8.6 High

CVSS3

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 3 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

CVSS3: 8.6
redhat
больше 3 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

CVSS3: 8.6
debian
около 3 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through ...

rocky
больше 3 лет назад

Important: squid security update

rocky
больше 3 лет назад

Important: squid:4 security update

EPSS

Процентиль: 37%
0.00157
Низкий

8.6 High

CVSS3

Дефекты

CWE-190
CWE-190