CVE-2004-0541

Squid Web Proxy Cache <3.x - RCE

Title source: llm

Description

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/16847
exploitdb WORKING POC VERIFIED
by skape · rubyremotemultiple
https://www.exploit-db.com/exploits/9951
metasploit WORKING POC GREAT
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/proxy/squid_ntlm_authenticate.rb

Scores

EPSS 0.7695
EPSS Percentile 99.0%

Details

Status published
Products (2)
national_science_foundation/squid_web_proxy_cache 2.5_stable
national_science_foundation/squid_web_proxy_cache 3_pre
Published Aug 06, 2004
Tracked Since Feb 18, 2026