← back
CVE-2004-0541

CVE-2004-0541

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 71%
from disclosure to weapon0 days
Published on NVDJun 10
1st PoCJun 8
metasploitJun 8
exploitation probability
71%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
4 products (52 components)
Red Hat Desktop version 3 · Red Hat Enterprise Linux AS version 3 · Red Hat Enterprise Linux ES version 3 · Red Hat Enterprise Linux WS version 3
Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.