Back

HIGH

squid: buffer-over-read in SSPI and SMB authentication

Published Dec 25, 2022

Description

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

Affected products

Remediation

Red Hat mitigation

Disable use of the vulnerable authentication scheme.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 25, 2022
Updated Apr 14, 2025
Reserved Sep 23, 2022
CISA Vulnrichment
Updated Apr 14, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 23, 2022