CVE-2004-0541 describes a critical buffer overflow vulnerability in Squid Web Proxy Cache versions 2.5.x and 3.x, specifically within the NTLM authentication function when NTLM handlers are enabled. This flaw allows remote, unauthenticated attackers to execute arbitrary code by supplying an excessively long password. With a CVSS score of 10.0, this vulnerability presents a severe risk, enabling full compromise of confidentiality, integrity, and availability. Exploit intelligence confirms the existence of public Metasploit modules, indicating readily available exploit code, and community discussion is notably high, suggesting significant awareness despite no active exploitation being reported in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5_stableCPE matchmatch criteria | cpe:2.3:a:national_science_foundation:squid_web_proxy_cache:2.5_stable:*:*:*:*:*:*:* | ||
3_preCPE matchmatch criteria | cpe:2.3:a:national_science_foundation:squid_web_proxy_cache:3_pre:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.