PT-2004-1650 · Squid · Squid Web Proxy Cache

Publicado

2004-06-10

·

Atualizado

2018-05-03

·

CVE-2004-0541

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Squid Web Proxy Cache versions 2.5.x through 3.x
Description The issue is related to a buffer overflow in the ntlm check auth function, which is used for NTLM authentication. This allows remote attackers to execute arbitrary code by providing a long password, specifically through the pass variable.
Recommendations For Squid Web Proxy Cache versions 2.5.x through 3.x, consider disabling NTLM authentication until a patch is available. Restrict access to the ntlm check auth function to minimize the risk of exploitation. Avoid using long passwords, especially those that could trigger the buffer overflow, until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0541
RHSA-2004:242

Produtos afetados

Squid Web Proxy Cache