← Vulnerability feed

Vulnerability record · CVE-2004-0541 · published 6 August 2004

CVE-2004-0541: Squid Web Proxy NTLM auth buffer overflow allows remote code execution

National Science Foundation · Squid Web Proxy Cache

Squid Web Proxy Cache 2.5.x and 3.x, when built with NTLM handlers enabled, contains a buffer overflow in the ntlm_check_auth function. A long password value overflows the buffer, and because the flaw is reachable over the network without authentication, it can lead to arbitrary code execution on the proxy.

10.0 CVSS 2.0 High EPSS 71% · top 0.6%
10.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with a network-reachable, unauthenticated buffer overflow that yields code execution, plus a very high EPSS percentile.

What it is

Squid Web Proxy Cache 2.5.x and 3.x, when built with NTLM handlers enabled, contains a buffer overflow in the ntlm_check_auth function. A long password value overflows the buffer, and because the flaw is reachable over the network without authentication, it can lead to arbitrary code execution on the proxy.

Impact

A remote attacker can execute arbitrary code with the privileges of the Squid process, giving full control of the proxy host. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.

Attack surface

Reachable over the network via the NTLM authentication handling path (AV:N, AC:L, Au:N), so no authentication or user interaction is required. It only applies to Squid builds compiled with NTLM handlers enabled.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.7107 (99.374th percentile), indicating a high modeled likelihood of exploitation. Several references carry Patch and Vendor Advisory tags, confirming fixes were published.

What to do

  • Upgrade to a patched Squid release from your distribution or vendor (Red Hat, Gentoo, Mandrake, Trustix, SGI advisories referenced).
  • If NTLM authentication is not required, rebuild Squid without NTLM handlers enabled to remove the vulnerable code path.
  • Restrict network access to the Squid proxy so only trusted clients can reach it.
  • Monitor vendor advisories for the affected 2.5.x and 3.x branches and apply follow-up updates.

Detection

  • Inspect Squid logs for NTLM authentication attempts with abnormally long password fields.
  • Alert on crashes or restarts of the squid process that coincide with NTLM auth traffic.
  • Use the referenced OVAL definitions to scan hosts for the vulnerable Squid build.
  • Watch for unexpected outbound connections or child processes spawned by squid.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc
http://fedoranews.org/updates/FEDORA--.shtml
http://www.gentoo.org/security/en/glsa/glsa-200406-13.xml PatchVendor Advisory
http://www.idefense.com/application/poi/display?id=107&type=vulnerabilities PatchVendor Advisory
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:059
http://www.redhat.com/support/errata/RHSA-2004-242.html PatchVendor Advisory
http://www.securityfocus.com/bid/10500
http://www.trustix.net/errata/2004/0033/ Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/16360
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10722
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A980
ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc
http://fedoranews.org/updates/FEDORA--.shtml
http://www.gentoo.org/security/en/glsa/glsa-200406-13.xml PatchVendor Advisory
http://www.idefense.com/application/poi/display?id=107&type=vulnerabilities PatchVendor Advisory
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:059
http://www.redhat.com/support/errata/RHSA-2004-242.html PatchVendor Advisory
http://www.securityfocus.com/bid/10500
http://www.trustix.net/errata/2004/0033/ Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/16360
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10722
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A980

Track CVE-2004-0541 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2004-0541), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.