Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2022-41318
HistoryDec 25, 2022 - 7:15 p.m.

CVE-2022-41318

2022-12-2519:15:10
Alpine Linux Development Team
security.alpinelinux.org
6
buffer over-read
squid
vulnerability
integer-overflow protection
sspi
smb authentication
cleartext credentials
unintended memory locations
unix

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

8.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.5%

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

OSVersionArchitecturePackageVersionFilename
Alpine3.15-mainnoarchsquid< 5.2-r1UNKNOWN
Alpine3.16-mainnoarchsquid< 5.2-r1UNKNOWN

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

8.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.5%