FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0541

This CVE name corresponds to:

Entered Topic
2004-06-09 Buffer overflow in Squid NTLM authentication helper

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0541
Phase Assigned(20040604)

Description

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

References

Source Reference
MISC http://www.idefense.com/application/poi/display?id=107&type=vulnerabilities
FEDORA FLSA-2006:152809
GENTOO GLSA-200406-13
REDHAT RHSA-2004:242
SUSE SuSE-SA:2004:016
MANDRAKE MDKSA-2004:059
TRUSTIX 2004-0033
SGI 20040604-01-U
BID 10500
OVAL oval:org.mitre.oval:def:10722
XF squid-ntlm-bo(16360)
OVAL oval:org.mitre.oval:def:980