VDB
CVE-2004-0541
CVE-2004-0541
PUBLISHED
CVSS 10 CRITICAL
Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).
EPSS 71.07% · 99.3th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
71.07%
99.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| national_science_foundation | squid_web_proxy_cache | 2.5_stable, * |
| n/a | n/a | * |
Timeline
- Jun 10, 2004 CVE Published
- Apr 30, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- oval:org.mitre.oval:def:10722 vdb
- RHSA-2004:242 vendor-advisory
- GLSA-200406-13 vendor-advisory
- 20040604-01-U vendor-advisory
- oval:org.mitre.oval:def:980 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2004-0541 advisory
- http://fedoranews.org/updates/FEDORA--.shtml url
- http://www.trustix.net/errata/2004/0033 url
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:059 technical
- http://www.securityfocus.com/bid/10500 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16360 technical
- http://www.idefense.com/application/poi/display?id=107&type=vulnerabilities patch
- http://www.trustix.net/errata/2004/0033/ advisory