A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.
[
    {
        "id": "CVE-2022-41318-0a2a77c1",
        "target": {
            "file": "src/ssl/support.cc"
        },
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "157750309172091702582925428005493227867",
                "218881333121098214655110636846154953560",
                "206051021408544867493777671469714873892",
                "70933281598196939590700626067890505816",
                "237286626667678540720639229716632419352",
                "12908433598266290249320675408114387116",
                "185234433191157783139533113985827305669",
                "91207162898924998580933656119642315529",
                "12830155845411348948611201853498301870",
                "98043717554064422388750680731084828886"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_type": "Line",
        "source": "https://github.com/squid-cache/squid/commit/5bb2694408e7a42897e9efe775361579d8864de8"
    },
    {
        "id": "CVE-2022-41318-1f50be07",
        "target": {
            "function": "Ssl::Initialize",
            "file": "src/ssl/support.cc"
        },
        "signature_version": "v1",
        "digest": {
            "length": 2417.0,
            "function_hash": "188390915243848524858308343346591833357"
        },
        "deprecated": false,
        "signature_type": "Function",
        "source": "https://github.com/squid-cache/squid/commit/5bb2694408e7a42897e9efe775361579d8864de8"
    },
    {
        "id": "CVE-2022-41318-f2e2486f",
        "target": {
            "file": "src/security/ServerOptions.cc"
        },
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "284090572366065137028192422215588986250",
                "19951007384723126726267253642941680731",
                "156669495693973190387507273863492603738",
                "301758475509959629984069537199932148530",
                "97161342785240974768606456605877618890",
                "169523640118712761496248132354948595410",
                "167510253363874404944685795350416904550",
                "135929239310644637345597208847357782135"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_type": "Line",
        "source": "https://github.com/squid-cache/squid/commit/5bb2694408e7a42897e9efe775361579d8864de8"
    }
]