QID 355074
Date Published: 2023-05-18
QID 355074: Amazon Linux Security Advisory for squid : AL2012-2023-398
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-41318:
A flaw was found in Squid. An incorrect integer overflow protection in the Squid SSPI and SMB authentication helpers is vulnerable to a buffer overflow attack, resulting in information disclosure or a denial of service.
2129771: CVE-2022-41318 squid: buffer-over-read in SSPI and SMB authentication
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 355074
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-398 | Amazon Linux Bare Metal |
|