Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-41318

Опубликовано: 23 сент. 2022
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

A flaw was found in Squid. An incorrect integer overflow protection in the Squid SSPI and SMB authentication helpers is vulnerable to a buffer overflow attack, resulting in information disclosure.

Меры по смягчению последствий

Disable use of the vulnerable authentication scheme.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidFixedRHSA-2022:681505.10.2022
Red Hat Enterprise Linux 8squidFixedRHSA-2022:677504.10.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionssquidFixedRHSA-2022:677404.10.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportsquidFixedRHSA-2022:677704.10.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportsquidFixedRHSA-2022:677604.10.2022
Red Hat Enterprise Linux 9squidFixedRHSA-2022:683906.10.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2129771squid: buffer-over-read in SSPI and SMB authentication

EPSS

Процентиль: 29%
0.001
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 2 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

CVSS3: 8.6
nvd
больше 2 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

CVSS3: 8.6
debian
больше 2 лет назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through ...

CVSS3: 7.5
redos
больше 2 лет назад

Уязвимость Squid

rocky
больше 2 лет назад

Important: squid:4 security update

EPSS

Процентиль: 29%
0.001
Низкий

8.6 High

CVSS3