Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-0541Improper Restriction of Operations within the Bounds of a Memory Buffer in Squid

12 documents8 sources
Severity
10.0CRITICALNVD
EPSS
77.0%
top 1.04%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedAug 6
Latest updateMay 3

Description

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

debiandebian/squid< squid 2.5.5-5 (bookworm)
Debiansquid/squid< 2.5.5-5+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c92g-qcfc-4869: Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 22022-05-03
OSV
CVE-2004-0541: Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 22004-08-06

💥Exploits & PoCs

3
Exploit-DB
Squid - NTLM (Authenticated) Overflow (Metasploit)2010-04-30
Exploit-DB
Squid 2.5.x/3.x - NTLM Buffer Overflow (Metasploit)2004-06-08
Metasploit
Squid NTLM Authenticate Overflow

📋Vendor Advisories

2
Red Hat
security flaw2004-06-08
Debian
CVE-2004-0541: squid - Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid ...2004

💬Community

4
Bugzilla
CVE-2004-0541 security flaw2018-08-16
Bugzilla
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-13452004-10-11
Bugzilla
CAN-2004-0541 Squid NTLM authentication helper overflow2004-06-09
Bugzilla
CAN-2004-0541 Squid NTLM authentication helper overflow2004-06-08