Logo
vulnerabilityCVE-2022-41318
Name
CVE-2022-41318
Source
NVD ( link)Debian ( link)
Description
A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
squid
Exploitable

Vulnerability Ratings#


8.6
CVSSv31
8.6
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.14
Not Affected
buildroot
master
7.6
Not Affected
openwrt
master
7.1-r1
Not Affected
openwrt
openwrt-25.12
7.1-r1
Not Affected
yocto
master
7.5
Not Affected
yocto
scarthgap
6.14
Not Affected