Out-of-bounds read in Squid - CVE-2022-41318

 

Out-of-bounds read in Squid - CVE-2022-41318

Published: September 23, 2022 / Updated: October 20, 2022


Vulnerability identifier: #VU67609
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41318
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information or crash the server.

The vulnerability exists due to a boundary condition within SSPI and SMB authentication helpers. A remote attacker can trigger an out-of-bounds read error and read contents of memory on the system or crash the server.

Successful exploitation of the vulnerability requires that Squid is configured to use NTLM or Negotiate authentication with one of the vulnerable helpers.


Affected software

Squid
Amazon Linux AMI
Debian Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Oracle Linux
CentOS
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Anolis OS
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
squid (Ubuntu package)
squid3 (Ubuntu package)
libecap
libecap-devel
squid-sysvinit
squid
squid-migration-script
squid (Red Hat package)
squid-debuginfo
squid-debugsource
squid (Debian package)

How to mitigate CVE-2022-41318

Install updates from vendor's website.

Squid - update to 5.7
squid (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.5.27-1ubuntu1.14, 4.10-1ubuntu1.7, 5.2-1ubuntu4.2
squid3 (Ubuntu package) - update to Ubuntu Pro
libecap - update to 1.0.1-2.0.1
libecap-devel - update to 1.0.1-2.0.1
squid-sysvinit - update to 3.5.20-17
squid - addressed in versions 3.5.20-17, 4.15-3
squid-migration-script - update to 3.5.20-17
squid (Red Hat package) - addressed in versions 3.5.20-17.el7_9.8, 5.2-1.el9_0.2
squid - update to 3.5.20-17.43
squid - addressed in versions 3.5.21-26.38.1, 4.17-4.27.1, 4.17-150000.5.35.1, 5.7-150400.3.6.1
squid-debuginfo - addressed in versions 3.5.21-26.38.1, 4.17-4.27.1, 4.17-150000.5.35.1, 5.7-150400.3.6.1
squid-debugsource - addressed in versions 3.5.21-26.38.1, 4.17-4.27.1, 4.17-150000.5.35.1, 5.7-150400.3.6.1
squid-debuginfo - update to 4.9-13
squid-debugsource - update to 4.9-13
squid - update to 4.9-13
squid (Debian package) - update to 4.13-10+deb11u2
squid - addressed in versions 5.7-1.fc35, 5.7-1.fc36, 5.7-1.fc37

External References

Related Security Bulletins